PT-2001-1964 · Igss · Air Messenger Lan Server
Published
2001-10-12
·
Updated
2008-09-05
·
CVE-2001-0785
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Air Messenger LAN Server version 3.4.2
Description
The issue allows remote attackers to read arbitrary files via a .. (dot dot) attack, which is a type of directory traversal attack. This attack takes advantage of the Webpaging interface in the affected software.
Recommendations
For Air Messenger LAN Server version 3.4.2, consider restricting access to the Webpaging interface until a patch is available. As a temporary workaround, limit the ability to read arbitrary files by implementing strict file system permissions.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Air Messenger Lan Server