PT-2008-2376 · Extreme · Extremez-Ip File/Print Server
Luigi Auriemma
·
Publicado
2008-02-13
·
Atualizado
2018-10-15
·
CVE-2008-0758
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ExtremeZ-IP File and Print Server versions 5.1.2x15 and earlier
Description
The issue allows remote attackers to read arbitrary files, including gif, png, jpg, xml, ico, zip, and html files, via a ".." (dot dot backslash) sequence in the filename. This is due to multiple directory traversal vulnerabilities in the Zidget/HTTP embedded HTTP server.
Recommendations
For ExtremeZ-IP File and Print Server versions 5.1.2x15 and earlier, consider restricting access to the Zidget/HTTP embedded HTTP server until a patch is available. As a temporary workaround, avoid using the ".." sequence in filenames to minimize the risk of exploitation.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Extremez-Ip File/Print Server