
The Cisco Internet Streamer application, part of the Cisco Content Delivery System, contains a directory traversal vulnerability on its web server component that allows for arbitrary file access. By exploiting this vulnerability, an attacker may be able to read arbitrary files on the device, outside of the web server document directory, by using a specially crafted URL.
An unauthenticated attacker may be able to exploit this issue to access sensitive information, including the password files and system logs, which could be leveraged to launch subsequent attacks.
All versions of system software on the Cisco Internet Streamer application are vulnerable prior to the first fixed release, but Cisco has released free software updates that address this vulnerability. Workarounds that mitigate this vulnerability are available.
This vulnerability can be exploited over all open HTTP ports; TCP ports 80 (Default HTTP port), 443 (Default HTTPS port) and 8090 (Alternate HTTP and HTTPS port), as well as those that are configured as part of the HTTP proxy.
As an interim step prior to upgrading the Cisco content delivery system software, it is possible to deny access to sensitive directories via service rules. The following example shows denying access to move up a directory level. This also caters for other directory moves, such as “\.\./”, “.\./” or “\../”:
rule enable
rule action block pattern-list 1
rule pattern-list 1 url-regex ^http://.*/../.*
rule pattern-list 1 url-regex ^https://.*/../.*
If you are affected by this issue or just want to read more please do it at http://www.cisco.com/warp/public/707/cisco-sa-20100721-spcdn.shtml.
Which WAN Optimization vendor will consolidate and expand its market position on 2011
447 votes - Thank you all!I add the results in a blog posts so we can see over years on which [more]
CCIE home rack - Ubuntu persistent net rules
In one of my last posts, I was writing about my CCIE home rack which has one server that runs Ubuntu + [more]
Black Friday 2011 - 50% Off on INE bundles
If anybody is interested in buying INE products, do it now. I've got the following marketing e-mail. The [more]
Free streaming course CCNA 640-802 from INE
I'm sure that a lot of people out there got this info already, but for those who are not part of INE [more]
Home lab for CCIE exam training
Before I started with my preparation I was in front of a dilemma. I knew that I will need a rack to [more]
Professionals Blogs
- noshut.blogspot.com
Close preview
Loading... - cisco-tips.com
Close preview
Loading... - packet-forwarding.net
Close preview
Loading... - brainbump.net
Close preview
Loading... - danielhertzberg.wordpress.com
Close preview
Loading... - blog.ioshints.info
Close preview
Loading... - packetlife.net
Close preview
Loading... - Cisco Network Engineer Blog
Close preview
Loading... - etherealmind.com
Close preview
Loading... - amyengineer.wordpress.com
Close preview
Loading... - blindhog.net
Close preview
Loading... - CCIECisco
Close preview
Loading... - globalconfig.net
Close preview
Loading... - routing-bits.com
Close preview
Loading... - mellowd.co.uk
Close preview
Loading... - bradhedlund.com
Close preview
Loading... - gns3-labs.com
Close preview
Loading...
- noshut.blogspot.com





Pingback: Tweets that mention Web Server Directory Traversal Vulnerability in Cisco CDS | FirstDigest -- Topsy.com