vendor:
Net Tools PKI Server
by:
SecurityFocus
8,8
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Net Tools PKI Server
Affected Version From: Network Associates Inc.'s Net Tools PKI Server
Affected Version To: Network Associates Inc.'s Net Tools PKI Server
Patch Exists: YES
Related CWE: CVE-2001-0206
CPE: o:network_associates:net_tools_pki_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2001
Directory Traversal Vulnerability in Network Associates Inc.’s Net Tools PKI Server
Network Associates Inc.'s Net Tools PKI (Public Key Infrastructure) server is vulnerable to a directory traversal attack. This vulnerability allows an attacker to read any file in the system which the PKI server resides, such as autoexec.bat, backup SAM files, etc. This is due to the failure of the web server to enforce a web root directory, allowing a user to move backward in the directory tree.
Mitigation:
Network Associates Inc. has released a patch to address this vulnerability.