EasyWeb FileManager Module Directory Traversal Vulnerability
BID:10792
Info
EasyWeb FileManager Module Directory Traversal Vulnerability
| Bugtraq ID: | 10792 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2004 12:00AM |
| Updated: | Jul 23 2004 12:00AM |
| Credit: | Discovery is credited to <[email protected]>. |
| Vulnerable: |
EasyWeb EasyWeb 1.0 RC-1 |
| Not Vulnerable: | |
Discussion
EasyWeb FileManager Module Directory Traversal Vulnerability
EasyWeb is prone to a directory traversal vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data. The issue occurs if a remote attacker sends a request to the 'ew_filemanager' script for a file containing directory traversal character sequences to the application.
EasyWeb FileManager 1.0 RC-1 is prone to this issue.
Update: Conflicting reports suggest that this issue may not be a vulnerability as access to various files can be limited by an EasyWeb administrator. An attacker with valid account credentials may only be able to carry out an attack. This BID will be updated as more information becomes available.
EasyWeb is prone to a directory traversal vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data. The issue occurs if a remote attacker sends a request to the 'ew_filemanager' script for a file containing directory traversal character sequences to the application.
EasyWeb FileManager 1.0 RC-1 is prone to this issue.
Update: Conflicting reports suggest that this issue may not be a vulnerability as access to various files can be limited by an EasyWeb administrator. An attacker with valid account credentials may only be able to carry out an attack. This BID will be updated as more information becomes available.
Exploit / POC
EasyWeb FileManager Module Directory Traversal Vulnerability
No exploit is required.
The following proof of concept is available:
/index.php?module=ew_filemanager&type=admin&func=manager&pathext=../../../etc
/index.php?module=ew_filemanager&type=admin&func=manager&pathext=../../../etc/&view=passwd
No exploit is required.
The following proof of concept is available:
/index.php?module=ew_filemanager&type=admin&func=manager&pathext=../../../etc
/index.php?module=ew_filemanager&type=admin&func=manager&pathext=../../../etc/&view=passwd
Solution / Fix
EasyWeb FileManager Module Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
EasyWeb FileManager Module Directory Traversal Vulnerability
References:
References:
- EasyWeb Homepage (EasyWeb)
- EasyWeb FileManager Directory Traversal ([email protected])
- Re: EasyWeb FileManager Directory Traversal (Noam Rathaus
)