Vulnerabilities > CVE-2006-1161 - Input Validation vulnerability in EFS Software EFS web Server 3.2

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
efs-software
nessus
exploit available

Summary

Absolute path traversal vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote registered users to execute arbitrary code by uploading a malicious file to the Windows startup folder.

Vulnerable Configurations

Part Description Count
Application
Efs_Software
1

Exploit-Db

descriptionEasy File Sharing Web Server 3.2 Full Path Request Arbitrary File Upload. CVE-2006-1161. Remote exploit for windows platform
idEDB-ID:27378
last seen2016-02-03
modified2006-03-09
published2006-03-09
reporterRevnic Vasile
sourcehttps://www.exploit-db.com/download/27378/
titleEasy File Sharing Web Server 3.2 Full Path Request Arbitrary File Upload

Nessus

NASL familyWeb Servers
NASL idEFS_FORMAT_STRING.NASL
descriptionThe remote host is running Easy File Sharing Web Server, a file sharing application / web server for Windows. The version of Easy File Sharing Web Server installed on the remote host may crash if it receives requests with an option parameter consisting of a format string. It is unknown whether this issue can be exploited to execute arbitrary code on the remote host, although it is likely the case. In addition, the application reportedly allows remote users to upload arbitrary files to arbitrary locations on the affected host. An attacker may be able to leverage this issue to completely compromise the host by placing them in the startup folder and waiting for a reboot. Additionally, it fails to sanitize input to the
last seen2020-06-01
modified2020-06-02
plugin id21039
published2006-03-10
reporterThis script is Copyright (C) 2006-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/21039
titleEasy File Sharing Web Server Multiple Remote Vulnerabilities (FS, XSS, Upload)