BusyBox HTTPD Directory Traversal Vulnerability
BID:20067
Info
BusyBox HTTPD Directory Traversal Vulnerability
| Bugtraq ID: | 20067 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-5050 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 16 2006 12:00AM |
| Updated: | Jul 06 2016 01:38PM |
| Credit: | <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
BusyBox Linux Utilities 1.01 |
| Not Vulnerable: | |
Discussion
BusyBox HTTPD Directory Traversal Vulnerability
The httpd daemon of BusyBox is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
This issue affects version 1.01; other versions may also be vulnerable.
The httpd daemon of BusyBox is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
This issue affects version 1.01; other versions may also be vulnerable.
Exploit / POC
BusyBox HTTPD Directory Traversal Vulnerability
Attackers can exploit this issue via a web client.
The following proof-of-concept URI is available:
http://www.example.com//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd
Attackers can exploit this issue via a web client.
The following proof-of-concept URI is available:
http://www.example.com//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd
Solution / Fix
BusyBox HTTPD Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
BusyBox HTTPD Directory Traversal Vulnerability
References:
References: