PT-2007-6779 · Sonicwall · Sonicwall Ssl-Vpn 2000/4000+1
Bernhard Mueller
+1
·
Publicado
2007-11-05
·
Atualizado
2018-10-15
·
CVE-2007-5815
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SonicWall SSL-VPN 200 versions prior to 2.1
SonicWall SSL-VPN 2000/4000 versions prior to 2.5
WebCacheCleaner ActiveX control version 1.3.0.3
Description
The issue allows remote attackers to delete arbitrary files via a full pathname in the argument to the
FileDelete method. This is due to an absolute path traversal vulnerability in the WebCacheCleaner ActiveX control.Recommendations
For SonicWall SSL-VPN 200 versions prior to 2.1, update to version 2.1 or later.
For SonicWall SSL-VPN 2000/4000 versions prior to 2.5, update to version 2.5 or later.
For WebCacheCleaner ActiveX control version 1.3.0.3, consider disabling the
FileDelete method until a patch is available.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sonicwall Ssl-Vpn 200
Sonicwall Ssl-Vpn 2000/4000