Path Traversal in DeWeS Web Server (Twilight CMS)
Advisory ID: | HTB23167 |
Product: | DeWeS web server (Twilight CMS) |
Vendor: | Strata Technologies LLC |
Vulnerable Versions: | 0.4.2 and probably prior |
Tested Version: | 0.4.2 |
Advisory Publication: | July 24, 2013 [without technical details] |
Vendor Notification: | July 24, 2013 |
Public Disclosure: | August 21, 2013 |
Vulnerability Type: | Path Traversal [CWE-22] |
CVE Reference: | CVE-2013-4900 |
Risk Level: | Medium |
CVSSv2 Base Score: | 5 (AV:N/AC:L/Au:N/C:P/I:N/A:N) |
Discovered and Provided: | High-Tech Bridge Security Research Lab |
Advisory Details: | |
High-Tech Bridge Security Research Lab discovered path traversal vulnerability in DeWeS web server that is supplied in package with Twilight CMS (Windows version), which can be exploited to read arbitrary files on vulnerable system. | |
Solution: | |
Currently we are not aware of any Vendor supplied patches or solutions. Vendor Notification Timeline: 2013-07-24 Vendor notification via email 2013-07-25 Vendor notification via email 2013-08-02 Vendor notification via email and online web form 2013-08-09 Vendor notification via email and online web form 2013-08-12 Vendor notification via email and online web form 2013-08-21 No single answer from Vendor, public disclosure | |
References: | |
[1] High-Tech Bridge Advisory HTB23167 - https://www.immuniweb.com/advisory/HTB23167 - Path Traversal in DeWeS [2] DeWeS - www.stratek.ru - DeWeS is a small web server for developers of Twilight CMS. [3] Common Vulnerabilities and Exposures (CVE) - http://cve.mitre.org/ - international in scope and free for public use, CVE® is a dictionary of publicly known information security vulnerabilities and exposures. [4] Common Weakness Enumeration (CWE) - http://cwe.mitre.org - targeted to developers and security practitioners, CWE is a formal list of software weakness types. | |
Please feel free to send us any additional information related to this Advisory, such as vulnerable versions, additional exploitation details and conditions, patches and other relevant details.