Chris Travers Hermes Unspecified File Include Vulnerability
BID:9173
Info
Chris Travers Hermes Unspecified File Include Vulnerability
| Bugtraq ID: | 9173 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2003 12:00AM |
| Updated: | Dec 08 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to the vendor. |
| Vulnerable: |
Chris Travers Hermes 0.3 .0 Alpha4 Chris Travers Hermes 0.3 .0 Alpha3 Chris Travers Hermes 0.3 .0 Alpha2 Chris Travers Hermes 0.3 .0 Alpha1 |
| Not Vulnerable: |
Chris Travers Hermes 0.3 .0 beta1 |
Discussion
Chris Travers Hermes Unspecified File Include Vulnerability
It has been reported that Hermes may be prone to an unspecified file include vulnerability that may allow an attacker to include malicious files containing arbitrary code to be executed on a vulnerable system.
Hermes versions 0.3.0 Alpha 4 and prior may be prone to this issue.
It has been reported that Hermes may be prone to an unspecified file include vulnerability that may allow an attacker to include malicious files containing arbitrary code to be executed on a vulnerable system.
Hermes versions 0.3.0 Alpha 4 and prior may be prone to this issue.
Exploit / POC
Chris Travers Hermes Unspecified File Include Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Chris Travers Hermes Unspecified File Include Vulnerability
Solution:
The vendor has released version 0.3.0 beta 1 of Hermes that is not vulnerable to this issue:
Chris Travers Hermes 0.3 .0 Alpha3
Chris Travers Hermes 0.3 .0 Alpha4
Chris Travers Hermes 0.3 .0 Alpha1
Chris Travers Hermes 0.3 .0 Alpha2
Solution:
The vendor has released version 0.3.0 beta 1 of Hermes that is not vulnerable to this issue:
Chris Travers Hermes 0.3 .0 Alpha3
-
SourceForge hermes-0.3.0-Beta1.tar.gz
http://prdownloads.sourceforge.net/hermesweb/hermes-0.3.0-Beta1.tar.gz ?download
Chris Travers Hermes 0.3 .0 Alpha4
-
SourceForge hermes-0.3.0-Beta1.tar.gz
http://prdownloads.sourceforge.net/hermesweb/hermes-0.3.0-Beta1.tar.gz ?download
Chris Travers Hermes 0.3 .0 Alpha1
-
SourceForge hermes-0.3.0-Beta1.tar.gz
http://prdownloads.sourceforge.net/hermesweb/hermes-0.3.0-Beta1.tar.gz ?download
Chris Travers Hermes 0.3 .0 Alpha2
-
SourceForge hermes-0.3.0-Beta1.tar.gz
http://prdownloads.sourceforge.net/hermesweb/hermes-0.3.0-Beta1.tar.gz ?download