Surfnet Kiosk Filesystem Access Vulnerability
BID:9346
Info
Surfnet Kiosk Filesystem Access Vulnerability
| Bugtraq ID: | 9346 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 02 2004 12:00AM |
| Updated: | Jan 02 2004 12:00AM |
| Credit: | Discovery is credited to <[email protected]>. |
| Vulnerable: |
Info Touch Surfnet 1.31 |
| Not Vulnerable: | |
Discussion
Surfnet Kiosk Filesystem Access Vulnerability
Surfnet kiosk software is prone to a vulnerability that may permit kiosk users to access the underlying filesystem. Users may access the underlying filesystem by attempting to access a 'file://' URI. This violates the security model of the software and could permit malicious individuals to abuse the system hosting the software.
Surfnet kiosk software is prone to a vulnerability that may permit kiosk users to access the underlying filesystem. Users may access the underlying filesystem by attempting to access a 'file://' URI. This violates the security model of the software and could permit malicious individuals to abuse the system hosting the software.
Exploit / POC
Surfnet Kiosk Filesystem Access Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Surfnet Kiosk Filesystem Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.