iPhone Configuration Web Utility 1.0 for Windows Directory Traversal
SecurityAlert : 4681 CVE : CVE-2008-5315 CWE : CWE-22 SecurityRisk : High (About) Remote Exploit : Yes Local Exploit : No Victim interaction required : No Exploit Available : No Credit : ddifrontline Published : 05.12.2008
Affected Software :
apple:iphone_configuration_web_utility:1.0
Advisory Content :
Title
-----
DDIVRT-DDIVRT-2008-15 iPhone Configuration Web Utility 1.0 for Windows
Directory Traversal
Severity
--------
High
Date Discovered
---------------
October 2, 2008
Discovered By
-------------
Digital Defense, Inc. Vulnerability Research Team
Credit: Corey LeBleu and r@b13$
Vulnerability Description
-------------------------
The iPhone Configuration Web Utility allows centralized management of
iPhone configuration settings. The iPhone Configuration Web Utility 1.0 for
Windows web interface is vulnerable to a common web directory traversal
attack. Successful exploitation will result in arbitrary read-only file
access outside of the iPhone Configuration Web Utility 1.0 web root.
Solution Description
--------------------
Filter network traffic so that only trusted users can access the web
interface.
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.