what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

FileVista Path Leakage / Path Write Modification

FileVista Path Leakage / Path Write Modification
Posted Nov 28, 2014
Authored by DS

FileVista versions prior to 6.1 leak internal path data and allow extraction outside of the stated path.

tags | advisory, info disclosure
advisories | CVE-2014-8788, CVE-2014-8789
SHA-256 | 3c41a9d024130c7bed75e3f82d0c36623aba0b5bbf2db458319d7eee03859fcb

FileVista Path Leakage / Path Write Modification

Change Mirror Download
Hi list,

FileVista is an IIS package which installs a file server onto Windows
Server systems. More information can be obtained from their website at
http://www.gleamtech.com/filevista.

CVE-2014-8788: The zip file handling routines in FileVista leaks internal
paths when users attempt to write a zip file to a path in which the
FileVista user account does not have Write access to. The internal path is
the path at which FileVista is installed onto
("c:\\inetpub\\wwwroot\\FileVista" by default).

CVE-2014-8789: The zip file extraction routine does not validate the stated
path of the extracted files. Malicious users may modify the contents of the
zip file to cause the constituent files to be extracted above the normal
zip file root path. In certain misconfigurations, this could cause the user
to write aspx files to the "wwwroot/FileVista" directory and execute
arbitrary code.

GleamTech has released a new version of the FileVista software (v6.1) which
addresses the above issues.

/DS


Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    28 Files
  • 16
    Jul 16th
    6 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close