vendor:
Timbuktu Pro
by:
titon
7.5
CVSS
HIGH
Arbitrary File Deletion/Creation
22
CWE
Product Name: Timbuktu Pro
Affected Version From: Timbuktu Pro <= 8.6.5
Affected Version To: Timbuktu Pro <= 8.6.5
Patch Exists: YES
Related CWE:
CPE: a:timbuktu_labs:timbuktu_pro:8.6.5
Platforms Tested:
2007
Timbuktu Pro <= 8.6.5 Arbitrary File Deletion/Creation
The Timbuktu Pro software version 8.6.5 and below is vulnerable to arbitrary file deletion and creation. This vulnerability can be exploited by an attacker to delete or create arbitrary files on the targeted system. The vulnerability occurs due to improper input validation when handling filenames, allowing an attacker to traverse directories and perform unauthorized file operations. This exploit takes advantage of the vulnerability by sending specially crafted packets to the target system. The payload can be either text or binary format.
Mitigation:
Upgrade to a patched version of Timbuktu Pro (version 8.6.6 or later) to mitigate this vulnerability. Additionally, ensure that the software is running on a secure and properly configured system.