Eye-Fi Helper < 3.4.23 Directory Traversal

This script is Copyright (C) 2013 Tenable Network Security, Inc.


Synopsis :

The remote Windows host has an application that is affected by a
directory traversal vulnerability.

Description :

The version of Eye-Fi Helper installed on the remote host is a version
prior to 3.4.23. It is, therefore, affected by a directory traversal
vulnerability because it fails to properly sanitize user- supplied
input.

An attacker could exploit this issue to overwrite arbitrary files on the
vulnerable computer, which could result in a denial of service or
arbitrary code execution.

See also :

http://www.pentest.co.uk/documents/ptl-2013-01.html
http://support.eye.fi/downloads/release-notes/center/

Solution :

Update to Eye-Fi Helper 3.4.23 or later.

Risk factor :

Low / CVSS Base Score : 2.9
(CVSS2#AV:A/AC:M/Au:N/C:N/I:P/A:N)
CVSS Temporal Score : 2.4
(CVSS2#E:F/RL:OF/RC:ND)
Public Exploit Available : true

Family: Web Servers

Nessus Plugin ID: 65688 ()

Bugtraq ID: 57163

CVE ID: CVE-2011-4696