OSVDB ID: 16069

Title: 602LAN SUITE mail A Parameter Traversal Arbitrary File Access

Info

Disclosure

Apr 29, 2005

Discovery

Unknown

Dates

Exploit

Apr 29, 2005

Solution

Unknown

Description

602LAN Suite contains a flaw that allows a remote attacker to enumerate arbitrary files outside of the web path. The issue is due to the mail script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the A variable, leading to loss of confidentiality. In addition, these requests could be scripted with the goal of consuming the server's resources, leading to a loss of availability.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Confidentiality
Solution: Upgrade
Exploit: Exploit Public
Disclosure: OSVDB Verified, Vendor Verified
OSVDB: Web Related

Solution

Upgrade to Build 2004.0.05.0509 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Software602

602LAN Suite

2004.0.05.0413

References

Credit

  • Dr_insane - dr_insanepathfinder.gr - Personal Page


Direct URL: http://osvdb.org/16069