ManageEngine Security Manager Plus 'f' Directory Traversal Arbitrary File Access

This script is Copyright (C) 2012-2013 Tenable Network Security, Inc.


Synopsis :

The remote web server is prone to a directory traversal attack.

Description :

The installed version of ManageEngine Security Manager Plus fails to
sanitize user-supplied input to the 'f' parameter of the 'store' request
page before using it to return the contents of a file.

An unauthenticated, remote attacker can leverage this issue to retrieve
arbitrary files through the web server using specially crafted requests
subject to the privileges under which the web server operates.

Note that this install is likely affected by other vulnerabilities,
though Nessus has not tested for these.

See also :

http://www.nessus.org/u?5c191c22

Solution :

Update to version 5.5 build 5506 or later.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS Temporal Score : 4.8
(CVSS2#E:F/RL:U/RC:ND)
Public Exploit Available : true

Family: CGI abuses

Nessus Plugin ID: 63206 ()

Bugtraq ID: 56139

CVE ID: