PT-2012-2036 · 3S · 3S Codesys

Luigi Auriemma

·

Published

2012-01-10

·

Updated

2017-08-29

·

CVE-2011-5058

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions 3S CoDeSys version 3.4 SP4 Patch 2
Description The issue allows remote attackers to create arbitrary directories under the web root by specifying a non-existent directory using backslash characters in an HTTP GET request. This is due to a flaw in the CmbWebserver.dll module of the Control service.
Recommendations For version 3.4 SP4 Patch 2, consider restricting access to the CmbWebserver.dll module until a patch is available. As a temporary workaround, avoid using backslash characters in HTTP GET requests to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-5058

Affected Products

3S Codesys