Gleamtech FileVista/FileUltimate 4.6 Directory Traversal

2012.11.29
Risk: High
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

Hello I have recently released this vulnerability in a talk: http://soroush.secproject.com/blog/2012/11/xss-by-uploadingincluding-a-swf-file/ - Title: GleamtechFileVista/FileUltimate 4.6 Directory Traversal can lead to file upload attack - Credit goes to: Soroush Dalili - Link:http://www.gleamtech.com/download - Description: It is possible to bypass directory traversal validation of FileVista/FileUltimate version 4.3 by using "..[SPACE]/" or "..[SPACE]\". As a result, it can be possible to bypass the security restrictions and upload an arbitrary file and execute that on the server. - PoC:http://www.youtube.com/v/HjS6Pob5t34?version=3&hl=en_US&rel=0&vq=hd720 Regards Soroush Dalili

References:

http://www.youtube.com/v/HjS6Pob5t34?version=3&hl=en_US&rel=0&vq=hd720
http://soroush.secproject.com/blog/2012/11/xss-by-uploadingincluding-a-swf-file/


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top