PT-2012-3038 · Cyberoam · Cyberoam Central Console
Published
2012-02-12
·
Updated
2012-02-25
·
CVE-2012-1047
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cyberoam Central Console versions 2.00.2
Description
A directory traversal issue exists in the WWWHELP Service, specifically in the js/html/wwhelp.htm file, allowing remote attackers to include and execute arbitrary local files. This is achieved by using a .. (dot dot) in the
file parameter within an Online help action.Recommendations
For version 2.00.2, consider restricting access to the
file parameter in the Online help action to prevent exploitation until a fix is available. As a temporary workaround, disabling the WWWHELP Service may also minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cyberoam Central Console