SlimServe HTTPD Directory Traversal Vulnerability
BID:14132
Info
SlimServe HTTPD Directory Traversal Vulnerability
| Bugtraq ID: | 14132 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0454 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2001 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Credit is given to [email protected] for discovering this vulnerability. |
| Vulnerable: |
WhitSoft SlimServe HTTPd 1.1 WhitSoft SlimServe HTTPd 1.0 |
| Not Vulnerable: | |
Discussion
SlimServe HTTPD Directory Traversal Vulnerability
SlimServe HTTP server is prone to directory traversal attacks due to improper sanitization of user input.
This type of attack allows a malicious user to read files that exist outside of the Web server root directory.
SlimServe HTTP server is prone to directory traversal attacks due to improper sanitization of user input.
This type of attack allows a malicious user to read files that exist outside of the Web server root directory.
Exploit / POC
SlimServe HTTPD Directory Traversal Vulnerability
No exploit is needed for this vulnerability. The following example was provided:
http://www.example.com/.../.../
No exploit is needed for this vulnerability. The following example was provided:
http://www.example.com/.../.../
Solution / Fix
SlimServe HTTPD Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SlimServe HTTPD Directory Traversal Vulnerability
References:
References:
- SlimServe HTTPd Homepage (Whitsoft)
- SlimServe HTTPd ver. 1.1a Directory Traversal ([email protected])
- WhitSoft Homepage (WhitSoft Development)