Symantec Mail-Gear Directory Traversal Vulnerability
BID:827
Info
Symantec Mail-Gear Directory Traversal Vulnerability
| Bugtraq ID: | 827 |
| Class: | Atomicity Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 29 1999 12:00AM |
| Updated: | Nov 29 1999 12:00AM |
| Credit: | Posted to bugtraq on November 29, 1999 by Ussr Labs <[email protected]>. |
| Vulnerable: |
Symantec Mail-Gear 1.0 |
| Not Vulnerable: |
Symantec Mail-Gear 1.1 |
Discussion
Symantec Mail-Gear Directory Traversal Vulnerability
Mail-Gear, a multi-purpose filtering email server, includes a webserver for remote administration and email retrieval. This webserver is vulnerable to the '../' directory traversal attack. By including the string '../' in the URL, remote attackers can gain read access to all files on the filesystem that the server has read access to.
Mail-Gear, a multi-purpose filtering email server, includes a webserver for remote administration and email retrieval. This webserver is vulnerable to the '../' directory traversal attack. By including the string '../' in the URL, remote attackers can gain read access to all files on the filesystem that the server has read access to.
Exploit / POC
Symantec Mail-Gear Directory Traversal Vulnerability
http: //target.host:8003/Display?what=../../../../../autoexec.bat
will display the server's autoexec.bat in a default NT installation.
http: //target.host:8003/Display?what=../../../../../autoexec.bat
will display the server's autoexec.bat in a default NT installation.
Solution / Fix
Symantec Mail-Gear Directory Traversal Vulnerability
Solution:
Upgrade to version 1.1, available at:
http://www.symantec.com/urlabs/public/download/download.html
Solution:
Upgrade to version 1.1, available at:
http://www.symantec.com/urlabs/public/download/download.html