ReGet Directory Traversal Bug May Cause Files to Be Downloaded to Arbitrary Locations
|
|
SecurityTracker Alert ID: 1009513
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Mar 22 2004
|
Impact: Modification of system information, Modification of user information
|
Exploit Included: Yes
|
Version(s): Tested on ReGet Deluxe 3.0 (build 121)
|
Description: An input validation vulnerability was reported in ReGet. Files may be downloaded to the wrong directory on the target system.
SECURITY.NNOV reported that a remote user can create a specially crafted filename containing encoded directory traversal characters
so that when the target user downloads the file using ReGet, the file will be written to an arbitrary location on the target user's
system.
For example, the following demonstration exploit filename will be saved to 'c:\etc\shadow' on the target user's system:
/support/download.jsp?filename=..%2F
..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fshadow
snifer at mailru333.com is credited
with reporting this flaw.
|
Impact: A remote user can cause a file downloaded by the target user to be written to an arbitrary location on the target user's system (subject to the privileges of the target user).
|
Solution: No solution was available at the time of this entry.
|
Vendor URL: www.regetsoft.com/ (Links to External Site)
|
Cause: Input validation error
|
Underlying OS: Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Mon, 22 Mar 2004 08:20:34 -0500
Subject: http://www.security.nnov.ru/search/document.asp?docid=5930
|
http://www.security.nnov.ru/search/document.asp?docid=5930
snifer@mailru333.com reported an input validation vulnerability in ReGet.
A remote user can create a specially crafted filename containing encoded
directory traversal characters to that when the target user downloads the file
using ReGet, the file will be written to an arbitrary location on the target
user's system.
For example, the following demonstration exploit filename will be saved to
'c:\etc\shadow' on the target user's system:
/support/download.jsp?filename=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F ..%2F..%2F..%2Fetc%2Fshadow
Tested on ReGet Deluxe 3.0 (build 121).
|
|