YaPig Password Protected Directory Access Vulnerability
BID:14099
Info
YaPig Password Protected Directory Access Vulnerability
| Bugtraq ID: | 14099 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 15 2003 12:00AM |
| Updated: | Nov 15 2003 12:00AM |
| Credit: | There is no information as to who should be credited for this vulnerability. |
| Vulnerable: |
YaPiG YaPig 0.94 u YaPiG YaPig 0.93 u YaPiG YaPig 0.92 b |
| Not Vulnerable: | |
Discussion
YaPig Password Protected Directory Access Vulnerability
YaPig is a Web-based image gallery application. Reportedly, it contains a flaw which will allow a malicious user to view images in password-protected directories. When viewing the HTML source created by the application, one may note that the full paths to image files are disclosed, resulting in unauthorized access to sensitive information.
YaPig is a Web-based image gallery application. Reportedly, it contains a flaw which will allow a malicious user to view images in password-protected directories. When viewing the HTML source created by the application, one may note that the full paths to image files are disclosed, resulting in unauthorized access to sensitive information.
Exploit / POC
YaPig Password Protected Directory Access Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
YaPig Password Protected Directory Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.