Viewing arbitrary file from the file system using Eshare Expressions 4 server
From: Alex Forkosh (aforkosh@techie.com)Date: 02/05/02
- Previous message: Kevin Day: "Re: Buffer overflow in mIRC allowing arbitary code to be executed."
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Alex Forkosh" <aforkosh@techie.com> To: <bugtraq@securityfocus.com> Date: Tue, 5 Feb 2002 00:18:42 -0600
There is a bug in Expressions server where you can view any file on the
drive that the server is installed on by using simple ../../
Example:
If eshare server Is installed at:
C:\eshare\expressions
And lets say this is an NT4.0 machine with os installed in c:\winnt
It is possible to pull win.ini file from winnt directory using
Proto://domainname.com/../../../../../winnt/win.ini
Any file can be viewed in the manner.
- Previous message: Kevin Day: "Re: Buffer overflow in mIRC allowing arbitary code to be executed."
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
Loading