Portcullis Security Advisory 05-010
From: Paul J Docherty (PJD_at_portcullis-security.com)
Date: 01/10/05
- Previous message: Team SHATTER (Application Security, Inc.): "[AppSecInc Team SHATTER Security Advisory] Microsoft Windows LPC heap overflow"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Mon, 10 Jan 2005 20:46:13 -0000 To: <bugtraq@securityfocus.com>
Portcullis Security Advisory
Vulnerable System:
MediaPartner 5.0
Vulnerability Title:
Directory Traversal Vulnerability and Cross Site Scripting Issue
Vulnerability discovery and development:
Portcullis Security Testing Service
Affected systems:
Emotion MediaPartner Web Server Version 5.0 (5.1 not confirmed)
Details:
The MediaPartner 5.0 web-server is vulnerable to directory
traversal. By specifying an HTTP request containing the string
'../' an attacker can gain access to files outside of the intended
web-published file system directory.
The directory-browsing page generated by the directory traversal
vulnerability is vulnerable to URL cross-site scripting
vulnerability.
Impact:
This allows an attacker to gain access to any file on the drive the
web-published file system is installed to.
An attacker can craft a URL that contains malicious code. When a
victim follows the URL the malicious code is executed by their
browser.
Exploit:
No exploit Code required. Examples: http://target_ip/../../../boot.ini
http://target_ip/../../