Big Brother file browsing Vulnerability
BID:142
Info
Big Brother file browsing Vulnerability
| Bugtraq ID: | 142 |
| Class: | Unknown |
| CVE: |
CVE-1999-1462 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 26 1999 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | This vulnerability was discovered by Michael Smith <[email protected]>. |
| Vulnerable: |
Sean MacGuire Big Brother 1.0 9c Sean MacGuire Big Brother 1.0 9b |
| Not Vulnerable: |
Sean MacGuire Big Brother 1.0 9d |
Discussion
Big Brother file browsing Vulnerability
Big Brother is a loosely-coupled distributed set of tools for monitoring and displaying the current status of an entire network and notifying the admin should need be. A vulnerability in the CGI script bb-hist.sh, the new history viewer, can be exploited to allow the partial display of local files provided they are readable by the user id CGI scripts are executed under by the web server, and that they are text based.
Big Brother is a loosely-coupled distributed set of tools for monitoring and displaying the current status of an entire network and notifying the admin should need be. A vulnerability in the CGI script bb-hist.sh, the new history viewer, can be exploited to allow the partial display of local files provided they are readable by the user id CGI scripts are executed under by the web server, and that they are text based.
Exploit / POC
Big Brother file browsing Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Big Brother file browsing Vulnerability
Solution:
Upgrade to Big Brother 1.09d or later.
Solution:
Upgrade to Big Brother 1.09d or later.
References
Big Brother file browsing Vulnerability
References:
References: