EasyGuppy Printfaq.PHP Directory Traversal Vulnerability
BID:14984
Info
EasyGuppy Printfaq.PHP Directory Traversal Vulnerability
| Bugtraq ID: | 14984 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2005 12:00AM |
| Updated: | Sep 30 2005 12:00AM |
| Credit: | Josh Zlatin-Amishav is credited with the discovery of this vulnerability. |
| Vulnerable: |
Guppy EasyGuppy 4.5.5 Guppy EasyGuppy 4.5.4 |
| Not Vulnerable: |
Guppy EasyGuppy 4.5.6 a |
Discussion
EasyGuppy Printfaq.PHP Directory Traversal Vulnerability
EasyGuppy is prone to a directory traversal vulnerability.
The application fails to properly sanitize input supplied through HTTP POST requests or cookies.
Exploitation of this vulnerability could lead to a loss of confidentiality as arbitrary files are disclosed to an attacker.
EasyGuppy is prone to a directory traversal vulnerability.
The application fails to properly sanitize input supplied through HTTP POST requests or cookies.
Exploitation of this vulnerability could lead to a loss of confidentiality as arbitrary files are disclosed to an attacker.
Exploit / POC
EasyGuppy Printfaq.PHP Directory Traversal Vulnerability
An exploit is not required.
An example URI has been provided:
http://www.example.com/printfaq.php?lng=en&pg=/../../../../../../../etc/passwd%00
An exploit is not required.
An example URI has been provided:
http://www.example.com/printfaq.php?lng=en&pg=/../../../../../../../etc/passwd%00
Solution / Fix
EasyGuppy Printfaq.PHP Directory Traversal Vulnerability
Solution:
The vendor has released version v4.5.6a to address this issue.
Guppy EasyGuppy 4.5.4
Guppy EasyGuppy 4.5.5
Solution:
The vendor has released version v4.5.6a to address this issue.
Guppy EasyGuppy 4.5.4
-
Guppy EasyGuppy
http://www.freeguppy.org/download.php?lng=en
Guppy EasyGuppy 4.5.5
-
Guppy EasyGuppy
http://www.freeguppy.org/download.php?lng=en
References
EasyGuppy Printfaq.PHP Directory Traversal Vulnerability
References:
References:
- GuppY Homepage (GuppY)
- BID #14752 update ([email protected])