IMPACT:
DoS, System access, Security Bypass
WHERE:
From local network
SOFTWARE:
KM Scanner File Utility 3.x
تنها کاربرانی که ثبت نام کرده
و وارد شده اند میتوانند لینک ها را مشاهده کنند.برای
ثبت نام کلیک کنید
DESCRIPTION:some vulnerabilities in KM Scanner File Utility has been reported which can be exploited to cause a DoS (Denial of Service), bypass certain security restrictions, and compromise a vulnerable system.
1) The problem is that the application improperly treats data
contained within incoming requests as authenticated. This can be
exploited to upload arbitrary files to the affected system.
2) An error in the upload functionality can be exploited to upload
arbitrary files to arbitrary locations via directory traversal
attacks.
NOTE: The vulnerabilities can be exploited by malicious people to upload malicious executables and compromise a vulnerable system.
3) Multiple errors in the processing of incoming network data can be
exploited to crash the application.
The vulnerabilities are reported in version 3.3.0.1. Other versions may also be affected.
SOLUTION:
Reportedly, the vendor has released a new version which fixes vulnerability #2 and Restrict network access to trusted users only..
source:
تنها کاربرانی که ثبت نام کرده
و وارد شده اند میتوانند لینک ها را مشاهده کنند.برای
ثبت نام کلیک کنید
تنها کاربرانی که ثبت نام کرده
و وارد شده اند میتوانند لینک ها را مشاهده کنند.برای
ثبت نام کلیک کنید