Verity Ultraseek Error Message Path Disclosure Vulnerability
BID:10275
Info
Verity Ultraseek Error Message Path Disclosure Vulnerability
| Bugtraq ID: | 10275 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0050 |
| Remote: | Yes |
| Local: | No |
| Published: | May 05 2004 12:00AM |
| Updated: | Jul 12 2009 04:07AM |
| Credit: | Discovery is credited to Corsaire. |
| Vulnerable: |
Verity Inc. Ultraseek 5.2.1 |
| Not Vulnerable: |
Verity Inc. Ultraseek 5.2.2 |
Discussion
Verity Ultraseek Error Message Path Disclosure Vulnerability
It has been reported that Verity Ultraseek search application is prone to a remote path disclosure vulnerability that may allow an attacker to disclose the server document root.
Verity Ultraseek 5.2.1 and prior versions are reported to be vulnerable to this issue.
It has been reported that Verity Ultraseek search application is prone to a remote path disclosure vulnerability that may allow an attacker to disclose the server document root.
Verity Ultraseek 5.2.1 and prior versions are reported to be vulnerable to this issue.
Exploit / POC
Verity Ultraseek Error Message Path Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Verity Ultraseek Error Message Path Disclosure Vulnerability
Solution:
Verity has released Ultraseek 5.2.2 to address this issue. Please contact the vendor to obtain a fixed version.
Solution:
Verity has released Ultraseek 5.2.2 to address this issue. Please contact the vendor to obtain a fixed version.
References
Verity Ultraseek Error Message Path Disclosure Vulnerability
References:
References:
- Ultraseek Product Page (Verity)
- Corsaire Security Advisory - Verity Ultraseek path disclosure issue ("advisories"
)