PT-2012-3024 · Enigma2 · Enigma2 Webinterface

Todor Donev

·

Published

2012-02-08

·

Updated

2012-02-08

·

CVE-2012-1025

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Enigma2 Webinterface versions 1.6.0 through 1.6.8 Enigma2 Webinterface version 1.6rc3 Enigma2 Webinterface version 1.7.0
Description The issue allows remote attackers to read arbitrary files via a full pathname in the file parameter. This is an absolute path traversal vulnerability in a file in the Enigma2 Webinterface.
Recommendations For Enigma2 Webinterface versions 1.6.0 through 1.6.8, consider restricting access to the file parameter to minimize the risk of exploitation. For Enigma2 Webinterface version 1.6rc3, avoid using the file parameter with full pathnames until the issue is resolved. For Enigma2 Webinterface version 1.7.0, restrict access to the vulnerable file to prevent arbitrary file reading.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1025

Affected Products

Enigma2 Webinterface