PT-2007-6779 · Sonicwall · Sonicwall Ssl-Vpn 2000/4000+1
Bernhard Mueller
+1
·
Published
2007-11-05
·
Updated
2018-10-15
·
CVE-2007-5815
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SonicWall SSL-VPN 200 versions prior to 2.1
SonicWall SSL-VPN 2000/4000 versions prior to 2.5
WebCacheCleaner ActiveX control version 1.3.0.3
Description
The issue allows remote attackers to delete arbitrary files via a full pathname in the argument to the
FileDelete method. This is due to an absolute path traversal vulnerability in the WebCacheCleaner ActiveX control.Recommendations
For SonicWall SSL-VPN 200 versions prior to 2.1, update to version 2.1 or later.
For SonicWall SSL-VPN 2000/4000 versions prior to 2.5, update to version 2.5 or later.
For WebCacheCleaner ActiveX control version 1.3.0.3, consider disabling the
FileDelete method until a patch is available.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sonicwall Ssl-Vpn 200
Sonicwall Ssl-Vpn 2000/4000