# PMS (XBMC) Web Server Security Vulnerability - Web Server Directory Traversal Arbitrary File Access

**URL:** <https://forums.plex.tv/t/pms-xbmc-web-server-security-vulnerability-web-server-directory-traversal-arbitrary-file-access/42152>\
**Category:** Dev/API Corner\
**Tags:** other-dev\
**Created:** [September 6, 2013, 12:28am UTC](https://forums.plex.tv/t/pms-xbmc-web-server-security-vulnerability-web-server-directory-traversal-arbitrary-file-access/42152 "2013-09-06T00:28:47Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![jamver](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/jamver/32/89668_2.png) [@jamver](https://forums.plex.tv/u/jamver)\
**Post date:** [September 6, 2013, 12:28am UTC](https://forums.plex.tv/t/pms-xbmc-web-server-security-vulnerability-web-server-directory-traversal-arbitrary-file-access/42152/1 "2013-09-06T00:28:47Z")

</div>

Hi Guys,  
&nbsp;  
Wasn't sure the appropriate forum to post this so I'm hoping this will do.  
&nbsp;  
I've just been running some network audits on my home LAN and noticed in the nessus scan reporting a (most likely) default configuration issue that need attention.  
&nbsp;  
--  
Web Server Directory Traversal Arbitrary File Access

```
Synopsis
The remote web server is affected by a directory traversal vulnerability.

Description  
It appears possible to read arbitrary files on the remote host outside the web server’s document directory using a specially crafted URL. An unauthenticated attacker may be able to exploit this issue to access sensitive information to aide in subsequent attacks.

Note that this plugin is not limited to testing for known vulnerabilities in a specific set of web servers. Instead, it attempts a variety of generic directory traversal attacks and considers a product to be vulnerable simply if it finds evidence of the contents of ‘/etc/passwd’ or a Windows ‘win.ini’ file in the response. It may, in fact, uncover ‘new’ issues, that have yet to be reported to the product’s vendor.

Solution  
Contact the vendor for an update, use a different product, or disable the service altogether.
```

```
Plugin Information

Plugin ID:
10297

Plugin Version:
$Revision: 1.104 $

Plugin Type:
remote

Plugin Publication Date:
1999/11/05

Plugin Last Modification Date:
2013/04/04
```

```
Risk Information

Risk Factor:
Medium

CVSS Base Score: 
5.0

CVSS Vector Score:
CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Temporal Vector: 
CVSS2#E:F/RL:OF/RC:C

CVSS Temporal Score:
4.1
```

```
Vulnerability Information
 
Exploit Available: 
true

Exploitability Ease:
Exploits are available

Exploitable With: Metasploit (Indusoft WebStudio NTWebServer Remote File Access) 
```

&nbsp;

Reference Information  
&nbsp;  
cve:&nbsp;[CVE-2013-2619](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-2619)&nbsp;[CVE-2012-5641](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-5641)&nbsp;[CVE-2012-5344](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-5344)&nbsp;[CVE-2012-5335](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-5335)&nbsp;[CVE-2012-5100](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-5100)&nbsp;[CVE-2012-1464](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1464)&nbsp;[CVE-2012-0697](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0697)&nbsp;[CVE-2011-4788](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4788)&nbsp;[CVE-2011-2524](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-2524)&nbsp;[CVE-2011-1900](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1900)&nbsp;[CVE-2010-4181](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-4181)&nbsp;[CVE-2010-3743](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3743)&nbsp;[CVE-2010-3488](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3488)&nbsp;[CVE-2010-3487](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3487)&nbsp;[CVE-2010-3459](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3459)&nbsp;[CVE-2010-1571](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1571)&nbsp;[CVE-2008-5315](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5315)&nbsp;[CVE-2000-0920](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2000-0920)  
  
osvdb:&nbsp;[89293](http://osvdb.org/89293)&nbsp;[88925](http://osvdb.org/88925)&nbsp;[82678](http://osvdb.org/82678)&nbsp;[82647](http://osvdb.org/82647)&nbsp;[80586](http://osvdb.org/80586)&nbsp;[79653](http://osvdb.org/79653)&nbsp;[78308](http://osvdb.org/78308)&nbsp;[78307](http://osvdb.org/78307)&nbsp;[74135](http://osvdb.org/74135)&nbsp;[73413](http://osvdb.org/73413)&nbsp;[72972](http://osvdb.org/72972)&nbsp;[72498](http://osvdb.org/72498)&nbsp;[72231](http://osvdb.org/72231)&nbsp;[70176](http://osvdb.org/70176)&nbsp;[68962](http://osvdb.org/68962)&nbsp;[68880](http://osvdb.org/68880)&nbsp;[68538](http://osvdb.org/68538)&nbsp;[68141](http://osvdb.org/68141)&nbsp;[68089](http://osvdb.org/68089)&nbsp;[68026](http://osvdb.org/68026)&nbsp;[65285](http://osvdb.org/65285)&nbsp;[64611](http://osvdb.org/64611)&nbsp;[64532](http://osvdb.org/64532)&nbsp;[50288](http://osvdb.org/50288)&nbsp;[3681](http://osvdb.org/3681)  
  
bid:&nbsp;[58794](http://www.securityfocus.com/bid/58794)&nbsp;[57313](http://www.securityfocus.com/bid/57313)&nbsp;[57143](http://www.securityfocus.com/bid/57143)&nbsp;[56871](http://www.securityfocus.com/bid/56871)&nbsp;[52541](http://www.securityfocus.com/bid/52541)&nbsp;[52327](http://www.securityfocus.com/bid/52327)&nbsp;[51399](http://www.securityfocus.com/bid/51399)&nbsp;[51311](http://www.securityfocus.com/bid/51311)&nbsp;[48926](http://www.securityfocus.com/bid/48926)&nbsp;[48114](http://www.securityfocus.com/bid/48114)&nbsp;[47987](http://www.securityfocus.com/bid/47987)&nbsp;[47842](http://www.securityfocus.com/bid/47842)&nbsp;[47760](http://www.securityfocus.com/bid/47760)&nbsp;[45603](http://www.securityfocus.com/bid/45603)&nbsp;[45599](http://www.securityfocus.com/bid/45599)&nbsp;[44586](http://www.securityfocus.com/bid/44586)&nbsp;[44564](http://www.securityfocus.com/bid/44564)&nbsp;[44393](http://www.securityfocus.com/bid/44393)&nbsp;[43830](http://www.securityfocus.com/bid/43830)&nbsp;[43358](http://www.securityfocus.com/bid/43358)&nbsp;[43356](http://www.securityfocus.com/bid/43356)&nbsp;[43258](http://www.securityfocus.com/bid/43258)&nbsp;[43230](http://www.securityfocus.com/bid/43230)&nbsp;[40680](http://www.securityfocus.com/bid/40680)&nbsp;[40133](http://www.securityfocus.com/bid/40133)&nbsp;[40053](http://www.securityfocus.com/bid/40053)&nbsp;[32412](http://www.securityfocus.com/bid/32412)&nbsp;[7715](http://www.securityfocus.com/bid/7715)&nbsp;[7544](http://www.securityfocus.com/bid/7544)&nbsp;[7378](http://www.securityfocus.com/bid/7378)&nbsp;[7362](http://www.securityfocus.com/bid/7362)&nbsp;[7308](http://www.securityfocus.com/bid/7308)  
  
edb-id:&nbsp;[24915](http://www.exploit-db.com/exploits/24915)  
&nbsp;

```
Plugin Output

3000 / tcp  
Service: www  
&nbsp;  
Nessus was able to retrieve the remote host’s password file using the following URL :
```

```
http://lounge-room-mac-mini.local.:3000/../../../../../../../../../../../../etc/passwd
```

```
Here are the contents :

------------------------------ snip ------------------------------
##
# User Database
#
# Note that this file is consulted directly only when the system is running
# in single-user mode. At other times this information is provided by
# Open Directory.
#
# See the opendirectoryd(8) man page for additional information about
# Open Directory.
##
nobody:*:-2:-2:Unprivileged User:/var/empty:/usr/bin/false
root:*:0:0:System Administrator:/var/root:/bin/sh
etc...
 
```

&nbsp;

---

<div class="post-metadata">

**Author:** ![FrozenDragoon](https://avatars.discourse-cdn.com/v4/letter/f/977dab/32.png) [@FrozenDragoon](https://forums.plex.tv/u/FrozenDragoon)\
**Post date:** [September 6, 2013, 12:35am UTC](https://forums.plex.tv/t/pms-xbmc-web-server-security-vulnerability-web-server-directory-traversal-arbitrary-file-access/42152/2 "2013-09-06T00:35:42Z")

</div>

Well.... look at that... crazy.

I'd post in the PMS forum as well, just to be safe.&nbsp;

Also, PMS is totally proprietary and has nothing to with XBMC, but better safe than sorry.&nbsp;

---

<div class="post-metadata">

**Author:** ![jamver](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/jamver/32/89668_2.png) [@jamver](https://forums.plex.tv/u/jamver)\
**Post date:** [September 6, 2013, 12:41am UTC](https://forums.plex.tv/t/pms-xbmc-web-server-security-vulnerability-web-server-directory-traversal-arbitrary-file-access/42152/3 "2013-09-06T00:41:33Z")

</div>

I thought PMS was derivative of XBMC.

If not, then why does the PMS port 3000 web server call itself XBMC?

---

<div class="post-metadata">

**Author:** ![jamver](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/jamver/32/89668_2.png) [@jamver](https://forums.plex.tv/u/jamver)\
**Post date:** [September 6, 2013, 12:43am UTC](https://forums.plex.tv/t/pms-xbmc-web-server-security-vulnerability-web-server-directory-traversal-arbitrary-file-access/42152/4 "2013-09-06T00:43:43Z")

</div>

Looks like somebody reported this in XBMC nearly 12 months ago:

[http://forum.xbmc.org/showthread.php?tid=144110](http://forum.xbmc.org/showthread.php?tid=144110)

and a couple of years before that:

[http://forum.xbmc.org/showthread.php?tid=81173](http://forum.xbmc.org/showthread.php?tid=81173)

and likely prior to that as well.

---

<div class="post-metadata">

**Author:** ![FrozenDragoon](https://avatars.discourse-cdn.com/v4/letter/f/977dab/32.png) [@FrozenDragoon](https://forums.plex.tv/u/FrozenDragoon)\
**Post date:** [September 6, 2013, 1:08am UTC](https://forums.plex.tv/t/pms-xbmc-web-server-security-vulnerability-web-server-directory-traversal-arbitrary-file-access/42152/5 "2013-09-06T01:08:38Z")

</div>

Plex Media Center (PMC) and Plex Home Theater (PHT) both are, but Plex Media Server (PMS) is not based on XBMC. &nbsp;

At least as far as I know.&nbsp;

Edit: Yea, that's strange. &nbsp;I'm not sure why PMS would be doing anything with port 3000... &nbsp;unless you are actually referring to PMC/PHT and said PMS by mistake?&nbsp;

But that's odd too... because what web server functions would PHT/PMC be running, when all "server" functions are served by PMS? Maybe the iOS/Android remote server or something...?&nbsp;

---

<div class="post-metadata">

**Author:** ![jamver](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/jamver/32/89668_2.png) [@jamver](https://forums.plex.tv/u/jamver)\
**Post date:** [September 8, 2013, 5:25am UTC](https://forums.plex.tv/t/pms-xbmc-web-server-security-vulnerability-web-server-directory-traversal-arbitrary-file-access/42152/6 "2013-09-08T05:25:26Z")

</div>

It's definitely PMS running on a Mac Mini that happens to be running the Plex Client as well.

At least it calls itself "PLEX Media Server"&nbsp;Version 0.9.8.4.125-ffe2a5d

---

<div class="post-metadata">

**Author:** ![jamver](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/jamver/32/89668_2.png) [@jamver](https://forums.plex.tv/u/jamver)\
**Post date:** [September 8, 2013, 5:40am UTC](https://forums.plex.tv/t/pms-xbmc-web-server-security-vulnerability-web-server-directory-traversal-arbitrary-file-access/42152/7 "2013-09-08T05:40:43Z")

</div>

I hadn't considered it could be the PMC causing this... but apparently it is!

So how do we get this bug fixed?

```
bash-3.2# lsof -i :3000
COMMAND   PID        USER   FD   TYPE             DEVICE SIZE/OFF NODE NAME
Plex    94884 mediaserver   20u  IPv4 0xadbe01c83f8c714f      0t0  TCP *:hbci (LISTEN)
```

```
bash-3.2# lsof -n +c 0 -V -i| grep -i plex
PlexHelper              375     mediaserver    1u  IPv4 0xadbe01c83b55ea97      0t0  UDP *:59299
PlexHelper              375     mediaserver    2u  IPv4 0xadbe01c84a8e733f      0t0  UDP *:62562
Plex\x20Media\x20Serv 61777     mediaserver   24u  IPv6 0xadbe01c842327c2f      0t0  TCP *:32443 (LISTEN)
Plex\x20Media\x20Serv 61777     mediaserver   39u  IPv6 0xadbe01c83daa73ef      0t0  TCP *:32400 (LISTEN)
Plex\x20Media\x20Serv 61777     mediaserver   56u  IPv6 0xadbe01c83f3c33ef      0t0  TCP 127.0.0.1:32400->127.0.0.1:58904 (TIME_WAIT)
Plex\x20Media\x20Serv 61777     mediaserver   60u  IPv4 0xadbe01c83a35edcf      0t0  UDP *:52102
Plex\x20Media\x20Serv 61777     mediaserver   67u  IPv4 0xadbe01c83a35d23f      0t0  UDP *:32410
Plex\x20Media\x20Serv 61777     mediaserver   68u  IPv4 0xadbe01c83a35c477      0t0  UDP *:32413
Plex\x20Media\x20Serv 61777     mediaserver   69u  IPv4 0xadbe01c83a35bfdf      0t0  UDP 127.0.0.1:55428
Plex\x20Media\x20Serv 61777     mediaserver   70u  IPv4 0xadbe01c83a35b6af      0t0  UDP 192.168.1.84:50527
Plex\x20Media\x20Serv 61777     mediaserver   71u  IPv4 0xadbe01c83ee40b97      0t0  UDP 127.0.0.1:53925
Plex\x20Media\x20Serv 61777     mediaserver   72u  IPv4 0xadbe01c83b55de57      0t0  UDP 192.168.1.84:57526
Plex\x20DLNA\x20Serve 61780     mediaserver   11u  IPv4 0xadbe01c843dd9fbf      0t0  TCP 127.0.0.1:53278->127.0.0.1:53277 (CLOSE_WAIT)
Plex\x20DLNA\x20Serve 61780     mediaserver   16u  IPv4 0xadbe01c83a35c2ef      0t0  UDP *:ssdp
Plex\x20DLNA\x20Serve 61780     mediaserver   19u  IPv4 0xadbe01c83fb03c9f      0t0  TCP *:blueberry-lm (LISTEN)
Plex\x20DLNA\x20Serve 61780     mediaserver   22u  IPv4 0xadbe01c8498d74c7      0t0  UDP *:9094
Plex\x20DLNA\x20Serve 61780     mediaserver   25u  IPv4 0xadbe01c83b55f6d7      0t0  UDP *:7572
Plex\x20DLNA\x20Serve 61780     mediaserver   28u  IPv4 0xadbe01c83b55f23f      0t0  UDP *:bnt-manager
Plex\x20DLNA\x20Serve 61780     mediaserver   31u  IPv4 0xadbe01c843dd7ba7      0t0  TCP *:32469 (LISTEN)
Plex\x20DLNA\x20Serve 61780     mediaserver   34u  IPv4 0xadbe01c83ee411b7      0t0  UDP *:62760
Plex\x20DLNA\x20Serve 61780     mediaserver   37u  IPv4 0xadbe01c83a35c5ff      0t0  UDP *:62026
Plex\x20DLNA\x20Serve 61780     mediaserver   55u  IPv4 0xadbe01c83b5624c7      0t0  UDP 192.168.1.84:61844->192.168.1.254:nat-pmp
Plex\x20DLNA\x20Serve 61780     mediaserver   60u  IPv4 0xadbe01c83a35edcf      0t0  UDP *:52102
Plex\x20DLNA\x20Serve 61780     mediaserver   61u  IPv6 0xadbe01c83c348c2f      0t0  TCP [::127.0.0.1]:32400->[::127.0.0.1]:53272 (TIME_WAIT)
Plex\x20DLNA\x20Serve 61780     mediaserver   62u  IPv6 0xadbe01c8410ee3ef      0t0  TCP [::127.0.0.1]:32400->[::127.0.0.1]:53273 (TIME_WAIT)
Plex\x20DLNA\x20Serve 61780     mediaserver   63u  IPv6 0xadbe01c83ca993ef      0t0  TCP [::127.0.0.1]:32400->[::127.0.0.1]:53274 (TIME_WAIT)
Plex                  94884     mediaserver    3u  IPv4 0xadbe01c8449db18f      0t0  UDP *:*
Plex                  94884     mediaserver   13u  IPv4 0xadbe01c8449da85f      0t0  UDP *:32415
Plex                  94884     mediaserver   14u  IPv4 0xadbe01c83b55eda7      0t0  UDP 127.0.0.1:50097
Plex                  94884     mediaserver   15u  IPv4 0xadbe01c8449da9e7      0t0  UDP 192.168.1.84:59729
Plex                  94884     mediaserver   16u  IPv4 0xadbe01c83a35d6d7      0t0  UDP *:32412
Plex                  94884     mediaserver   20u  IPv4 0xadbe01c83f8c714f      0t0  TCP *:hbci (LISTEN)
Plex                  94884     mediaserver   21u  IPv4 0xadbe01c83ee5ac9f      0t0  TCP *:websm (LISTEN)
Plex                  94884     mediaserver   22u  IPv4 0xadbe01c8498d71b7      0t0  UDP *:9777
```

---

<div class="post-metadata">

**Author:** ![FrozenDragoon](https://avatars.discourse-cdn.com/v4/letter/f/977dab/32.png) [@FrozenDragoon](https://forums.plex.tv/u/FrozenDragoon)\
**Post date:** [September 8, 2013, 1:41pm UTC](https://forums.plex.tv/t/pms-xbmc-web-server-security-vulnerability-web-server-directory-traversal-arbitrary-file-access/42152/8 "2013-09-08T13:41:47Z")

</div>

Well, PMC will not be receiving any future updates. PHT, when released, will take its place. That said, PHT is still based on XBMC code (12.2), so I wonder if the bug is still there in PHT?  
  
  
The rest of the technical details are over my head, but I do see the process listening on 32400, which would make it PMS and not PMC, I think.  
  
  
And truthfully, I’m not sure the best way to bring this to anyone’s attention.

---

<div class="post-metadata">

**Author:** ![jamver](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/jamver/32/89668_2.png) [@jamver](https://forums.plex.tv/u/jamver)\
**Post date:** [September 9, 2013, 12:27am UTC](https://forums.plex.tv/t/pms-xbmc-web-server-security-vulnerability-web-server-directory-traversal-arbitrary-file-access/42152/9 "2013-09-09T00:27:20Z")

</div>

Well, as I said, this is actually in PMC so it's possible nobody will actually care (sadly). &nbsp;(hbci is port 3000 as listed in OS X's /etc/services)

I'm going to take a stab in the dark and guess that PHT will have the same problem, but I've not tried it yet. &nbsp;Now might be the time to have a closer look at it (I thought it was mean to be a replacement for both PMC and PMS though...)

---

<div class="post-metadata">

**Author:** ![jamver](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/jamver/32/89668_2.png) [@jamver](https://forums.plex.tv/u/jamver)\
**Post date:** [September 9, 2013, 7:09am UTC](https://forums.plex.tv/t/pms-xbmc-web-server-security-vulnerability-web-server-directory-traversal-arbitrary-file-access/42152/10 "2013-09-09T07:09:27Z")

</div>

PHT is in the clear - so just an issue with PMC.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/plex/original/3X/2/a/2acb9765406f63293d357b4ec509ec39aa28f2ad.png) [@system](https://forums.plex.tv/u/system)\
**Post date:** [December 21, 2019, 12:02am UTC](https://forums.plex.tv/t/pms-xbmc-web-server-security-vulnerability-web-server-directory-traversal-arbitrary-file-access/42152/11 "2019-12-21T00:02:47Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
