VDG Security Sense Multiple Security Vulnerabilities
BID:71736
Info
VDG Security Sense Multiple Security Vulnerabilities
| Bugtraq ID: | 71736 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-9451 CVE-2014-9452 CVE-2014-9575 CVE-2014-9576 CVE-2014-9577 CVE-2014-9578 CVE-2014-9579 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2014 12:00AM |
| Updated: | Mar 08 2015 04:04PM |
| Credit: | SEC Consult Vulnerability Lab |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
VDG Security Sense Multiple Security Vulnerabilities
VDG Security Sense is prone to the following security vulnerabilities:
1. An arbitrary file-download vulnerability
2. An authentication-bypass vulnerability
3. Multiple security bypass vulnerabilities
4. Multiple information-disclosure vulnerabilities
5. Multiple stack-based buffer-overflow vulnerabilities
An attacker may leverage these issues to execute arbitrary code in the context of the vulnerable site, download arbitrary files from the web server, bypass the authentication mechanism and gain unauthorized access, and obtain potentially sensitive information.
VDG Security Sense 2.3.13 is vulnerable; other versions may also be affected.
VDG Security Sense is prone to the following security vulnerabilities:
1. An arbitrary file-download vulnerability
2. An authentication-bypass vulnerability
3. Multiple security bypass vulnerabilities
4. Multiple information-disclosure vulnerabilities
5. Multiple stack-based buffer-overflow vulnerabilities
An attacker may leverage these issues to execute arbitrary code in the context of the vulnerable site, download arbitrary files from the web server, bypass the authentication mechanism and gain unauthorized access, and obtain potentially sensitive information.
VDG Security Sense 2.3.13 is vulnerable; other versions may also be affected.
Exploit / POC
VDG Security Sense Multiple Security Vulnerabilities
Attackers can exploit these issues using browser.
The following example URI is available:
http://www.example.com/images/../../../../Windows/SysWOW64/config/systemprofile/AppData/Roaming/Diva/Settings/users.ini
Attackers can exploit these issues using browser.
The following example URI is available:
http://www.example.com/images/../../../../Windows/SysWOW64/config/systemprofile/AppData/Roaming/Diva/Settings/users.ini
Solution / Fix
VDG Security Sense Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
VDG Security Sense Multiple Security Vulnerabilities
References:
References: