ID
VAR-201105-0313
TITLE
Vordel Gateway Directory Traversal Vulnerability
Trust: 0.9
DESCRIPTION
The Vordel XML gateway is an XML gateway device. There is a problem with the Vordel XML gateway management interface. A remote attacker can send a URL request for a directory traversal sequence to port 8090, bypassing the WEB ROOT limit, and gain access to passwords and configuration files. Vordel Gateway is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input. A remote attacker could exploit this vulnerability using directory-traversal strings (such as '../') to gain access to arbitrary files on the targeted system. This may result in the disclosure of sensitive information or lead to a complete compromise of the affected computer. Vordel Gateway 6.0.3 is vulnerable; other versions may also be affected
Trust: 0.81
IOT TAXONOMY
category: | ['Network device'] | sub_category: | - | Trust: 0.6 |
AFFECTED PRODUCTS
vendor: | vordel | model: | limited vordel gateway | scope: | eq | version: | 6.0.3 | Trust: 0.9 |
vendor: | vordel | model: | limited vordel gateway | scope: | ne | version: | 6.1 | Trust: 0.3 |
THREAT TYPE
network
Trust: 0.3
TYPE
Input Validation Error
Trust: 0.3
PATCH
title: | Vordel Gateway directory traversal vulnerability patch | url: | https://www.cnvd.org.cn/patchinfo/show/3963 | Trust: 0.6 |
EXTERNAL IDS
db: | BID | id: | 47975 | Trust: 0.9 |
db: | CNVD | id: | CNVD-2011-1999 | Trust: 0.6 |
REFERENCES
url: | https://www.upsploit.com/index.php/advisories/view/ups-2011-0023 | Trust: 0.9 |
url: | http://www.vordel.com/ | Trust: 0.3 |
CREDITS
Brian W. Gary
Trust: 0.3
SOURCES
db: | CNVD | id: | CNVD-2011-1999 |
db: | BID | id: | 47975 |
LAST UPDATE DATE
2022-05-17T02:01:22.053000+00:00
SOURCES UPDATE DATE
db: | CNVD | id: | CNVD-2011-1999 | date: | 2011-05-26T00:00:00 |
db: | BID | id: | 47975 | date: | 2011-05-25T00:00:00 |
SOURCES RELEASE DATE
db: | CNVD | id: | CNVD-2011-1999 | date: | 2011-05-26T00:00:00 |
db: | BID | id: | 47975 | date: | 2011-05-25T00:00:00 |