Qbik WinGate Information Disclosure Vulnerability

BID:10646

Info

Qbik WinGate Information Disclosure Vulnerability

Bugtraq ID: 10646
Class: Input Validation Error
CVE: CVE-2004-0577
CVE-2004-0578
Remote: Yes
Local: No
Published: Jul 01 2004 12:00AM
Updated: Jul 12 2009 05:16AM
Credit: An anonymous contributor is credited with discovery.
Vulnerable: Qbik WinGate Pro 6.0 Beta 2 Build 942
Qbik WinGate Pro 5.2.3 Build 901
Qbik WinGate Pro 5.0.5
Qbik WinGate Plus 6.0 Beta 2 Build 942
Qbik WinGate Plus 5.2.3 Build 901
Qbik WinGate Plus 5.0.5
Not Vulnerable:

Discussion

Qbik WinGate Information Disclosure Vulnerability

WinGate is reported susceptible to an information disclosure vulnerability in its HTTP proxy server.

An internal web server contained in WinGate improperly allows attackers access to read arbitrary files outside of its document root. WinGate by default runs as the localsystem user, therefore this vulnerability allows remote attackers to read system files.

An attacker can exploit this issue to read arbitrary files contained on the WinGate computer. These files may contain sensitive information that may aid in further attacks.

Exploit / POC

Qbik WinGate Information Disclosure Vulnerability

No exploit is required.

Solution / Fix

Qbik WinGate Information Disclosure Vulnerability

Solution:
The vendor has released an upgrade dealing with this issue.


Qbik WinGate Plus 5.0.5

Qbik WinGate Pro 5.0.5

Qbik WinGate Plus 5.2.3 Build 901

Qbik WinGate Pro 5.2.3 Build 901

Qbik WinGate Pro 6.0 Beta 2 Build 942

Qbik WinGate Plus 6.0 Beta 2 Build 942

References

Qbik WinGate Information Disclosure Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report