safenet-inc.comConfirmation
http://safenet-inc.com/support/files/SPI740SecurityPatch.zip CVE-2007-6483
SafeNet Sentinel Protection Server 7.x/Keys Server 1.0.3 - Directory Traversal
Record summary
CVE-2007-6483 has a selected CVSS score of 5.0; EIP currently links 2 catalogued exploits.
Description
Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier versions, and Sentinel Keys Server 1.0.3 and possibly earlier versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the query string.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBSafeNet Sentinel Protection Server 7.x/Keys Server 1.0.3 - Directory TraversalExploitDB exploitby Corey LebleuNot analyzed1 file
ExploitDBSafeNet Sentinel Protection Server 7.0 < 7.4 / Sentinel Keys Server 1.0.3 < 1.0.4 - Directory TraversalExploitDB exploitby Matt SchmidtNot analyzed1 file
References
1127811Third-party advisory
http://secunia.com/advisories/27811 3471Third-party advisory
http://securityreason.com/securityalert/3471 20071126 2007-06 Sentinel Protection Server Directory Traversalmailing list
http://www.securityfocus.com/archive/1/484201/100/200/threaded 20071126 Directory Traversal in SafeNet Sentinel Protection Server and Keys Servermailing list
http://www.securityfocus.com/archive/1/484224/100/200/threaded 26583vdb entry
http://www.securityfocus.com/bid/26583 1018992vdb entry
http://www.securitytracker.com/id?1018992 ADV-2007-4011vdb entry
http://www.vupen.com/english/advisories/2007/4011 sentinel-protection-directory-traversal(38636)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/38636 ics-cert.us-cert.gov
https://ics-cert.us-cert.gov/advisories/ICSA-15-272-01 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-6483