27469Third-party advisory
http://secunia.com/advisories/27469 CVE-2007-5815
SonicWALL SSL VPN 1.3 3 WebCacheCleaner - ActiveX FileDelete Method Traversal Arbitrary File Deletion
Record summary
CVE-2007-5815 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Absolute path traversal vulnerability in the WebCacheCleaner ActiveX control 1.3.0.3 in SonicWall SSL-VPN 200 before 2.1, and SSL-VPN 2000/4000 before 2.5, allows remote attackers to delete arbitrary files via a full pathname in the argument to the FileDelete method.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSonicWALL SSL VPN 1.3 3 WebCacheCleaner - ActiveX FileDelete Method Traversal Arbitrary File DeletionExploitDB exploitby Will DormannNot analyzed1 file
References
93342Third-party advisory
http://securityreason.com/securityalert/3342 sec-consult.com
http://www.sec-consult.com/303.html sec-consult.com
http://www.sec-consult.com/fileadmin/Advisories/20071101-0_sonicwall_multiple.txt 20071101 SEC Consult SA-20071101-0 :: Multiple Vulnerabilities in SonicWALLSSL-VPN Clientmailing list
http://www.securityfocus.com/archive/1/483097/100/0/threaded 26288vdb entry
http://www.securityfocus.com/bid/26288 ADV-2007-3696vdb entry
http://www.vupen.com/english/advisories/2007/3696 sonicwall-webcachecleaner-file-delete(38221)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/38221 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-5815