Mono XSP Unspecified Directory Traversal Vulnerability
BID:19929
CVE-2006-2658 |Info
Mono XSP Unspecified Directory Traversal Vulnerability
| Bugtraq ID: | 19929 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-2658 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2006 12:00AM |
| Updated: | Sep 11 2006 06:48PM |
| Credit: | A anonymous user is credited with the discovery of this vulnerability. |
| Vulnerable: |
S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 10.1 Mono XSP 0 |
| Not Vulnerable: | |
Discussion
Mono XSP Unspecified Directory Traversal Vulnerability
XSP is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the webserver process. Information obtained may aid in further attacks.
XSP is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the webserver process. Information obtained may aid in further attacks.
Exploit / POC
Mono XSP Unspecified Directory Traversal Vulnerability
Attackers can exploit this vulnerability with a standard web browser.
Attackers can exploit this vulnerability with a standard web browser.
Solution / Fix
Mono XSP Unspecified Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Third-party vendor advisories that address this issue are available.
Please see the references for more information.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Third-party vendor advisories that address this issue are available.
Please see the references for more information.