| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.801526 |
| Kategorie: | Web Servers |
| Titel: | Visual Synapse HTTP Server Directory Traversal Vulnerability |
| Zusammenfassung: | Check directory traversal attack on Visual Synapse HTTP Server |
| Beschreibung: | Overview: This host is running Visual Synapse HTTP Server and is prone to directory traversal vulnerability. Vulnerability Insight: An input validation error is present in the server which fails to validate user supplied request URI containing 'dot dot' sequences (/..\). Impact: Successful exploitation will allow attacker to launch directory traversal attack and gain sensitive information about the remote system's directory contents. Impact Level: System/Application Affected Software/OS: Visual Synapse HTTP Server 1.0 RC3, 1.0 RC2, 1.0 RC1 and 0.60 and prior Fix: No solution or patch is available as of 18th October, 2010. Information regarding this issue will be updated once the solution details are available. For updates refer to http://sourceforge.net/projects/visualsynapse/ References: http://www.exploit-db.com/exploits/15216/ http://www.syhunt.com/?n=Advisories.Vs-httpd-dirtrav http://www.securityfocus.com/archive/1/archive/1/514167/100/0/threaded |
| Querverweis: |
BugTraq ID: 43830 Common Vulnerability Exposure (CVE) ID: CVE-2010-3743 Bugtraq: 20101007 Syhunt Advisory: Visual Synapse HTTP Server Directory Traversal Vulnerability (Google Search) http://www.securityfocus.com/archive/1/archive/1/514167/100/0/threaded http://www.exploit-db.com/exploits/15216 http://www.syhunt.com/advisories/?id=vs-httpd-dirtrav http://www.securityfocus.com/bid/43830 |
| Copyright | Copyright (c) 2010 Greenbone Networks GmbH |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|