CGI Script Center Auction Weaver Arbitrary File Deletion Vulnerability
BID:1782
Info
CGI Script Center Auction Weaver Arbitrary File Deletion Vulnerability
| Bugtraq ID: | 1782 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 12 2000 12:00AM |
| Updated: | Oct 12 2000 12:00AM |
| Credit: | Discovered by Steve Christey <[email protected]> on October 12, 2000. |
| Vulnerable: |
CGI Script Center Auction Weaver 1.0 4 CGI Script Center Auction Weaver 1.0 3 CGI Script Center Auction Weaver 1.0 2 CGI Script Center Auction Weaver 1.0 1 CGI Script Center Auction Weaver 1.0 |
| Not Vulnerable: |
CGI Script Center Auction Weaver 1.0 5 |
Discussion
CGI Script Center Auction Weaver Arbitrary File Deletion Vulnerability
Auction Weaver does not perform proper sanity checking within certain form fields. It is possible for any remote user to delete arbitrary files and directories through the use of the double dot "..". This affects files and directories within and outside of the web root.
While deleting an entire directory, Auction Weaver may fail when attempting to delete any subdirectories. However, any files above the subdirectory would have been successfully deleted.
Auction Weaver does not perform proper sanity checking within certain form fields. It is possible for any remote user to delete arbitrary files and directories through the use of the double dot "..". This affects files and directories within and outside of the web root.
While deleting an entire directory, Auction Weaver may fail when attempting to delete any subdirectories. However, any files above the subdirectory would have been successfully deleted.
Exploit / POC
CGI Script Center Auction Weaver Arbitrary File Deletion Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
CGI Script Center Auction Weaver Arbitrary File Deletion Vulnerability
Solution:
CGI Script Center has addressed this vulnerability with the release of Auction Weaver 1.05. It is available for download at the following location:
http://www.cgiscriptcenter.com/awl/
Solution:
CGI Script Center has addressed this vulnerability with the release of Auction Weaver 1.05. It is available for download at the following location:
http://www.cgiscriptcenter.com/awl/
References
CGI Script Center Auction Weaver Arbitrary File Deletion Vulnerability
References:
References:
- Auction Weaver Product Homepage (CGI Script Center)