Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY through 8.2 SIM 24, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary code via a crafted HTTP request, aka ZDI-CAN-1622.
Vector
NETWORK
Complexity
LOW
Authentication
NONE
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL
Simbirsk Technologies, Ltd CS-Cart 2.0.7
Simbirsk Technologies, Ltd CS-Cart 2.1
Simbirsk Technologies, Ltd CS-Cart 2.0.6
Simbirsk Technologies, Ltd CS-Cart 2.0.9
Simbirsk Technologies, Ltd CS-Cart 2.0.8
Simbirsk Technologies, Ltd CS-Cart 3.0
Ge Intelligent platforms proficy hmi%2fscada cimplicity 8.2 Sim24 (not an official CPE)
Advisory | Patch | Confirmed | Link |
---|---|---|---|
http://support.ge-ip.com/support/index?page=kbchannel&id... | |||
http://ics-cert.us-cert.gov/advisories/ICSA-14-023-01 | |||
65124 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (ID 22)
Related CAPEC 7
Relative Path Traversal (CAPEC-ID 139)
Directory Traversal (CAPEC-ID 213)
File System Function Injection, Content Based (CAPEC-ID 23)
Using Slashes and URL Encoding Combined to Bypass Validation Logic (CAPEC-ID 64)
Manipulating Input to File System Calls (CAPEC-ID 76)
Using Escaped Slashes in Alternate Encoding (CAPEC-ID 78)
Using Slashes in Alternate Encoding (CAPEC-ID 79)