[NT] Directory Traversal Bug Found in QuickFront Web Server

From: support@securiteam.com
Date: 04/18/03

  • Next message: support@securiteam.com: "[NT] iWeb Mini Web Server Remote Directory Traversal"
    From: support@securiteam.com
    To: list@securiteam.com
    Date: 18 Apr 2003 12:20:41 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    In the US?

    Contact Beyond Security at our new California office
    housewarming rates on automated network vulnerability
    scanning. We also welcome ISPs and other resellers!

    Please contact us at: 323-882-8286 or ussales@beyondsecurity.com
    - - - - - - - - -

      Directory Traversal Bug Found in QuickFront Web Server
    ------------------------------------------------------------------------

    SUMMARY

     <http://www.matriks.com/> QuickFront is a "web server written in Delphi.
    It's easy and powerful for use". A directory traversal vulnerability has
    been found in the product allowing a remote attacker to download files
    that reside outside the bounding HTTP root directory.

    DETAILS

    Vulnerable systems:
     * QuickFront web server version 1.0.0.189

    Immune systems:
     * QuickFront web server build 2002.0.02.0916

    When attacker send request to server in this form:
     http:// server>/../../../../../boot.ini

    The server will return the boot.ini file.

    Solution:
    Vendor was contacted 11/03/2003. The solution is install latest version
    2002.0.02.0916.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:jkachlik@isgroup.com>
    Kachlik Jan.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: support@securiteam.com: "[NT] iWeb Mini Web Server Remote Directory Traversal"

    Relevant Pages

    • SecurityFocus Microsoft Newsletter #102
      ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows Media Player File Attachment Script Execution... ... Microsoft TSAC ActiveX Control Buffer Overflow Vulnerability ... Abyss Web Server Malicious HTTP Request Information Disclosure... ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #95
      ... MICROSOFT VULNERABILITY SUMMARY ... BEA Systems WebLogic Server and Express Race Condition Denial... ... Key Focus KF Web Server Directory Contents Disclosure... ... KMMail Code Injection Vulnerability ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #93
      ... cyber attacks and bulletproof countermeasures to prevent attacks before ... MICROSOFT VULNERABILITY SUMMARY ... YaBB Invalid Topic Error Page Cross Site Scripting Vulnerability ... GameCheats Advanced Web Server Malformed HTTP Request Denial Of... ...
      (Focus-Microsoft)
    • [NT] Xedus Webserver Directory Traversal and DoS
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The Xedus web server is vulnerable to a directory traversal. ... this vulnerability constitutes a denial of ...
      (Securiteam)
    • RE: New HP Jetdirect SNMP password vulnerability when using Web JetAdmin
      ... The issue at hand stems from the fact that the web server in older ... If you set the snmp community string to anything other than the ... New HP Jetdirect SNMP password vulnerability when using Web ... -A Web Jetadmin "device password" had been set on the JetDirect card. ...
      (Bugtraq)