[NT] WebServer 4 Everyone Directory Traversal Bug
From: support@securiteam.comDate: 09/08/02
- Previous message: support@securiteam.com: "[NEWS] Multiple Vulnerabilities at Canada.com"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Sun, 8 Sep 2002 23:08:11 +0200 (CEST)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
WebServer 4 Everyone Directory Traversal Bug
------------------------------------------------------------------------
SUMMARY
<http://www.freeware.lt/body_w4a_us.html> WebServer 4 Everyone is an easy
to use web server, however, the product has been found to contain a
security vulnerability that would allow an attacker to cause it to display
files that reside outside the bounding HTML root directory.
DETAILS
Vulnerable systems:
* WebServer 4 Everyone version 1.22
Immune systems:
* WebServer 4 Everyone version 1.23
A security problem is caused by the character '\' (%5c). Since it is not
filtered out from incoming requests, the server will follow the path in
the URI that the attacker give until it reaches the file requested.
Example:
http://host/%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cboot.ini
Or
GET /\..\..\..\..\..\boot.ini HTTP/1.0
ADDITIONAL INFORMATION
The information has been provided by <mailto:cuctema@ok.ru> UkR security
team.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[NEWS] Multiple Vulnerabilities at Canada.com"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|