AnomicHTTPProxy Directory Traversal Vulnerability
BID:10732
Info
AnomicHTTPProxy Directory Traversal Vulnerability
| Bugtraq ID: | 10732 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2004 12:00AM |
| Updated: | Jul 15 2004 12:00AM |
| Credit: | Discovery of this vulnerability is unknown at this time. |
| Vulnerable: |
Anomic.de AnomicHTTPProxy 0.21 _build20040627 |
| Not Vulnerable: |
Anomic.de AnomicHTTPProxy 0.22 _build20040711 |
Discussion
AnomicHTTPProxy Directory Traversal Vulnerability
It is reported that AnomicHTTPProxy is prone to a directory traversal vulnerability.
This issue would allow an attacker to view arbitrary files on the affected computer that the UID of AnomicHTTPProxy is running as. This may aid an attacker in conducting further attacks against the vulnerable computer.
Version 0.21_build20040627 is reported vulnerable. Prior versions may also be affected.
It is reported that AnomicHTTPProxy is prone to a directory traversal vulnerability.
This issue would allow an attacker to view arbitrary files on the affected computer that the UID of AnomicHTTPProxy is running as. This may aid an attacker in conducting further attacks against the vulnerable computer.
Version 0.21_build20040627 is reported vulnerable. Prior versions may also be affected.
Exploit / POC
AnomicHTTPProxy Directory Traversal Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
AnomicHTTPProxy Directory Traversal Vulnerability
Solution:
The vendor has released version 0.22_build20040711 dealing with this, and other issues.
Anomic.de AnomicHTTPProxy 0.21 _build20040627
Solution:
The vendor has released version 0.22_build20040711 dealing with this, and other issues.
Anomic.de AnomicHTTPProxy 0.21 _build20040627
-
Anomic.de AnomicHTTPProxy_v0.22_build20040711.tar.gz
http://www.anomic.de/AnomicHTTPProxy/release/AnomicHTTPProxy_v0.22_bui ld20040711.tar.gz