PT-2001-1964 · Igss · Air Messenger Lan Server
Publicado
2001-10-12
·
Atualizado
2008-09-05
·
CVE-2001-0785
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Air Messenger LAN Server version 3.4.2
Description
The issue allows remote attackers to read arbitrary files via a .. (dot dot) attack, which is a type of directory traversal attack. This attack takes advantage of the Webpaging interface in the affected software.
Recommendations
For Air Messenger LAN Server version 3.4.2, consider restricting access to the Webpaging interface until a patch is available. As a temporary workaround, limit the ability to read arbitrary files by implementing strict file system permissions.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Air Messenger Lan Server