iXsecurity.20020316.csadmin_dir.a

From: Patrik Karlsson (Patrik.Karlssonat_private)
Date: Wed Apr 03 2002 - 07:58:47 PST

  • Next message: Steven M. Christey: "Re: Multiple Vulnerabilties Sambar Webserver"

    iXsecurity Security Vulnerability Report
    No: iXsecurity.20020316.csadmin_dir.a
    ========================================
    
    Vulnerability Summary
    ---------------------
    Problem:                Cisco Secure ACS webserver has a directory
    traversal
                            issue.
    
    Threat:                 An attacker could retrieve any html, htm, class,
                            jpg, jpeg or gif file outside of the webroot.
    
    Affected Software:      Cisco Secure ACS 2.6.X and 3.0.1 (build 40).
    
    Platform:               Windows NT/2000.
    
    Solution:               Install the patch from Cisco.
    
    Vulnerability Description
    -------------------------
    Cisco Secure ACS has a webserver interface listening on port 2002.
    It is possible for a logged in user to read files outside the webdirectory.
    After a succesfull login, one could supply eg.
    http://>:<dynamicport>/..\..\..\..\..\..\temp\temp.class to read the
    contents
    of the file temp.class in the folder temp on the same volume that the
    software
    is installed.
    
    Solution
    --------
    Cisco PSIRT can confirm this vulnerability. The Security Advisory
    was published and it is at
    http://www.cisco.com/warp/public/707/ACS-Win-Web.shtml
    Only Cisco ACS for Windows is affected. The Unix version is not
    affected by these issues. You can download patches by following
    instructions in the Advisory.
    
    Additional Information
    ----------------------
    Cisco was contacted 20020316.
    
    
    This vulnerability was found and researched by
    Jonas Ländin, jonas.landinat_private
    Patrik Karlsson, patrik.karlssonat_private
    



    This archive was generated by hypermail 2b30 : Wed Apr 03 2002 - 16:25:40 PST