Relative Path Vulnerability in WinWrapper Professional 2.0
A vulnerability exists in ASCII NT Products WinWrapper 2.0 Professional firewall software that lets an attacker read files on the vulnerable system under the local system security context.
August 26, 2001
Reported August 21, 2001, by AraiYu.
VERSION AFFECTED
ASCII NT Products WinWrapper 2.0 Professional
DESCRIPTION
Avulnerability exists in ASCII NT Products WinWrapper 2.0 Professional firewallsoftware that lets an attacker read files on the vulnerable system under thelocal system security context. By using the remote service port (4096) that thesystem opens for Web-based administration, an attacker can traverse the remotesystem file structure using relative paths to read arbitrary data.
DEMONSTRATION
Arai Yu posted the following example asproof-of-concept:
http://IP_Address_of_WinWrapper:4096/../../../winnt/repair/sam
Typing the preceding line downloads a copy of the SAMdatabase from the vulnerable system.
VENDOR RESPONSE
The vendor, ASCIINT Products, has released version 2.0.1that fixes this vulnerability.
CREDIT
Discovered by AraiYu.
About the Author
You May Also Like