PT-2007-6779 · Sonicwall · Sonicwall Ssl-Vpn 2000/4000+1

Bernhard Mueller

+1

·

Published

2007-11-05

·

Updated

2018-10-15

·

CVE-2007-5815

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SonicWall SSL-VPN 200 versions prior to 2.1 SonicWall SSL-VPN 2000/4000 versions prior to 2.5 WebCacheCleaner ActiveX control version 1.3.0.3
Description The issue allows remote attackers to delete arbitrary files via a full pathname in the argument to the FileDelete method. This is due to an absolute path traversal vulnerability in the WebCacheCleaner ActiveX control.
Recommendations For SonicWall SSL-VPN 200 versions prior to 2.1, update to version 2.1 or later. For SonicWall SSL-VPN 2000/4000 versions prior to 2.5, update to version 2.5 or later. For WebCacheCleaner ActiveX control version 1.3.0.3, consider disabling the FileDelete method until a patch is available.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5815

Affected Products

Sonicwall Ssl-Vpn 200
Sonicwall Ssl-Vpn 2000/4000