Easy File Sharing Web Server Multiple Remote Vulnerabilities (FS, XSS, Upload)

high Nessus Plugin ID 21039

Synopsis

The remote web server suffers from a format string vulnerability.

Description

The remote host is running Easy File Sharing Web Server, a file sharing application / web server for Windows.

The version of Easy File Sharing Web Server installed on the remote host may crash if it receives requests with an option parameter consisting of a format string. It is unknown whether this issue can be exploited to execute arbitrary code on the remote host, although it is likely the case.

In addition, the application reportedly allows remote users to upload arbitrary files to arbitrary locations on the affected host. An attacker may be able to leverage this issue to completely compromise the host by placing them in the startup folder and waiting for a reboot.

Additionally, it fails to sanitize input to the 'Description' field when creating a folder or uploading a file, which could lead to cross-site scripting attacks.

Note that by default the application runs with the privileges of the user who started it, although it can be configured to run as a service.

Solution

Unknown at this time.

See Also

https://www.securityfocus.com/archive/1/427158/30/0/threaded

Plugin Details

Severity: High

ID: 21039

File Name: efs_format_string.nasl

Version: 1.23

Type: remote

Family: Web Servers

Published: 3/10/2006

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.6

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Information

Required KB Items: Settings/ThoroughTests

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 3/9/2006

Reference Information

CVE: CVE-2006-1159, CVE-2006-1160, CVE-2006-1161

BID: 17046

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990