WebSVN 'dl.php' Arbitrary File Access Vulnerability
BID:72301
Info
WebSVN 'dl.php' Arbitrary File Access Vulnerability
| Bugtraq ID: | 72301 |
| Class: | Design Error |
| CVE: |
CVE-2013-6892 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 19 2015 12:00AM |
| Updated: | Jan 19 2015 12:00AM |
| Credit: | James Clawson |
| Vulnerable: |
WebSVN WebSVN 0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
WebSVN WebSVN 2.3.3-1.2 WebSVN WebSVN 2.3.3-1.1+deb7u1 WebSVN WebSVN 2.3.1-1+deb6u1 |
Discussion
WebSVN 'dl.php' Arbitrary File Access Vulnerability
WebSVN is prone to an arbitrary file-access vulnerability.
An attacker can exploit this issue to retrieve or delete arbitrary files, which may aid in further attacks.
WebSVN is prone to an arbitrary file-access vulnerability.
An attacker can exploit this issue to retrieve or delete arbitrary files, which may aid in further attacks.
Exploit / POC
WebSVN 'dl.php' Arbitrary File Access Vulnerability
An attacker can use a browser to exploit this issue.
An attacker can use a browser to exploit this issue.
Solution / Fix
WebSVN 'dl.php' Arbitrary File Access Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
WebSVN 'dl.php' Arbitrary File Access Vulnerability
References:
References: