PT-2008-2376 · Extreme · Extremez-Ip File/Print Server

Luigi Auriemma

·

Publicado

2008-02-13

·

Atualizado

2018-10-15

·

CVE-2008-0758

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ExtremeZ-IP File and Print Server versions 5.1.2x15 and earlier
Description The issue allows remote attackers to read arbitrary files, including gif, png, jpg, xml, ico, zip, and html files, via a ".." (dot dot backslash) sequence in the filename. This is due to multiple directory traversal vulnerabilities in the Zidget/HTTP embedded HTTP server.
Recommendations For ExtremeZ-IP File and Print Server versions 5.1.2x15 and earlier, consider restricting access to the Zidget/HTTP embedded HTTP server until a patch is available. As a temporary workaround, avoid using the ".." sequence in filenames to minimize the risk of exploitation.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0758

Produtos afetados

Extremez-Ip File/Print Server