[NT] VisNetic WebSite Path Disclosure Vulnerability

From: SecuriTeam (support_at_securiteam.com)
Date: 07/07/03

  • Next message: SecuriTeam: "[NEWS] XBOX Dashboard Local Vulnerability"
    To: list@securiteam.com
    Date: 7 Jul 2003 17:37:19 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    Beyond Security in Canada

    Toronto-based Sunrays Technologies is now Beyond Security's representative in Canada.
    We welcome ISPs, system integrators and IT systems resellers
    to promote the most advanced vulnerability assessment solutions today.

    Contact us at 416-482-0038 or at canadasales@beyondsecurity.com

    - - - - - - - - -

      VisNetic WebSite Path Disclosure Vulnerability
    ------------------------------------------------------------------------

    SUMMARY

     <http://www.deerfield.com/download/visnetic_website/> VisNetic Website,
    "the first web server developed specifically for Windows, can use almost
    any development platform, and includes features that allow web developers
    to create powerful, flexible web sites. VisNetic WebSite is a secure
    windows-based web server that supports multiple domains, and allows
    TLS/SSL secured domains. This web server also includes support for a user
    database that can restrict access to content, and is immune to many of the
    security issues that may arise with other popular web servers". A
    vulnerability in the product allows remote attackers to cause the server
    to reveal the path it has been installed under.

    DETAILS

    Vulnerable systems:
     * VisNetic WebSite 3.5, Service release 17

    When requesting a certain file from the /_vti_bin/ folder (a folder that
    doesn't exist), an error message will be returned. This error message will
    reveal the local path of the web folder under which the product has been
    installed.

    Example:
    http://www.somehost.com/_vti_bin/fpcount.exe/

    Will return the following error (including the local path of the installed
    webpage):
    500 Server Error

    The server encountered an error and was unable to complete your request.

    Message: Empty output from CGI program c:/localpath/_vti_bin/fpcount.exe

    Please contact the server administrator at postmaster@somehost.com and
    inform them of the time the error occurred, plus anything you know of that
    may have caused the error.

    As you can see, the data returned by VisNetic Website, includes
    information about the local file system.

    Solution:
    The problem should, according to VisNetic, have been resolved in the
    latest build of VisNetic WebSite. The latest version is available on the
    VisNetic Website download page.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:kruse@krusesecurity.dk>
    Peter Kruse.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NEWS] XBOX Dashboard Local Vulnerability"

    Relevant Pages

    • [NT] VisNetic WebSite Denial of Service
      ... Beyond Security would like to welcome Tiscali World Online ... VisNetic WebSite is a secure ... Windows-based web server that supports multiple domains, ... It should be noted that an attack will still be caught in the log file for ...
      (Securiteam)
    • VisNetic WebSite Denial of Service
      ... Software affected: VisNetic WebSite 3.5.13.1 ... This Advisory is copyright by Peter Kruse. ... Windows-based web server that supports multiple domains, ... and is immune to many of the security ...
      (NT-Bugtraq)
    • [NT] VisNetic WebSite XSS vulnerability through HTTP Referer header
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Beyond Security would like to welcome Tiscali World Online ... VisNetic WebSite is a secure ... Windows-based web server that supports multiple domains, ...
      (Securiteam)
    • [NT] Webserver 4D Weak Password Preservation Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... complete Web Server environment written entirely on top of 4th Dimension, ... WS4D web server saves the passwords somewhere insecure. ...
      (Securiteam)
    • [NT] Poisoning Cached HTTPS Documents in Internet Explorer
      ... Get your security news from a reliable source. ... "poison" a user's browser cache with a malicious document that will later ... The attacker can exploit this vulnerability for "replacing" HTML ... to communicate with a malicious web server over HTTPS without the browser ...
      (Securiteam)