PT-2003-1258 · Sun · Sun One Starter Kit

Publicado

2003-03-18

·

Atualizado

2008-09-05

·

CVE-2002-1525

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sun ONE Starter Kit version 2.0
Description A directory traversal issue exists in the ASTAware SearchDisk engine, allowing remote attackers to read arbitrary files. This can be achieved through a .. (dot dot) attack on ports 6015 or 6016, or by using an absolute pathname to access port 6017.
Recommendations For Sun ONE Starter Kit version 2.0, restrict access to ports 6015, 6016, and 6017 to minimize the risk of exploitation. As a temporary workaround, consider disabling the ASTAware SearchDisk engine until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1525

Produtos afetados

Sun One Starter Kit