Vulnerability CVE-2010-0620


Published: 2010-02-24   Modified: 2012-02-13

Description:
Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitrary code, via a .. (dot dot) in an unspecified parameter.

See advisories in our WLB2 database:
Topic
Author
Date
High
EMC HomeBase Server Directory Traversal Remote Code Execution
metasploit
04.05.2011

Type:

CWE-22

(Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
EMC -> Homebase server 

 References:
http://securityreason.com/securityalert/8230
http://www.securityfocus.com/archive/1/509723/100/0/threaded
http://www.securityfocus.com/bid/38380
http://www.vupen.com/english/advisories/2010/0458
http://www.zerodayinitiative.com/advisories/ZDI-10-020/

Copyright 2024, cxsecurity.com

 

Back to Top