ACTi Web Configurator cgi-bin Directory Traversal

2012.04.27
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-22

Title ----- DDIVRT-2012-41 ACTi Web Configurator cgi-bin Directory Traversal Severity -------- High Date Discovered --------------- March 8, 2012 Discovered By ------------- Digital Defense, Inc. Vulnerability Research Team Credit: shmoov and r@b13$ Vulnerability Description ------------------------- The ACTi Web Configurator 3.0 for ACTi IP Surveillance Cameras contains a directory traversal vulnerability within the cgi-bin directory. An unauthenticated remote attacker can use this vulnerability to retrieve arbitrary files that are located outside the root of the web server. Solution Description -------------------- The production of the cameras employing this version of the ACTi Web Configurator have been discontinued. However, a firmware upgrade which addresses the issue is available for download from the ACTi support team. Please contact the ACTi support team to retrieve the firmware upgrade and instructions on how to apply the changes. Tested Systems / Software ------------------------- ACTi Web Configurator 3.0 - camera version unknown Vendor Contact -------------- Vendor Name: ACTi Corporation | http://www.acti.com/corporate/Brief.asp Vendor Website: http://www.acti.com/home/index.asp

References:

http://www.acti.com/corporate/Brief.asp


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top