10

CVE-2011-1565

Exploit
Directory traversal vulnerability in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to (1) read (opcode 0x3) or (2) create or write (opcode 0x2) arbitrary files via ..\ (dot dot backslash) sequences to TCP port 12401.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
7tIgss
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 64.06% 0.991
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

http://aluigi.org/adv/igss_1-adv.txt
Exploit
http://secunia.com/advisories/43849
Vendor Advisory
http://securityreason.com/securityalert/8178
http://www.exploit-db.com/exploits/17024
Exploit
http://www.securityfocus.com/bid/46936
Exploit
http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-080-03.pdf
US Government Resource
http://www.vupen.com/english/advisories/2011/0741
Vendor Advisory