Easy File Sharing Web Server Information Disclosure and Input Validation Vulnerabilities
BID:20823
Info
Easy File Sharing Web Server Information Disclosure and Input Validation Vulnerabilities
| Bugtraq ID: | 20823 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2006 12:00AM |
| Updated: | Oct 31 2006 11:07PM |
| Credit: | Greg Linares is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
EFS Software Easy File Sharing Web Server 4.0 |
| Not Vulnerable: | |
Discussion
Easy File Sharing Web Server Information Disclosure and Input Validation Vulnerabilities
Easy File Sharing Web Server is prone to information-disclosure and input-validation vulnerabilities. The application fails to properly sanitize user-supplied input before using it in dynamically generated content.
The issues include HTML-injection, cross-site scripting, and arbitrary information-disclosure vulnerabilities.
An attacker can exploit these issues to steal cookie-based authentication credentials, control how the site is rendered to the user, and gain access to otherwise confidential information. Successful exploits may facilitate a compromise of the underlying computer.
Version 4.0 of Easy File Sharing Web Server is vulnerable; other versions may also be affected.
Easy File Sharing Web Server is prone to information-disclosure and input-validation vulnerabilities. The application fails to properly sanitize user-supplied input before using it in dynamically generated content.
The issues include HTML-injection, cross-site scripting, and arbitrary information-disclosure vulnerabilities.
An attacker can exploit these issues to steal cookie-based authentication credentials, control how the site is rendered to the user, and gain access to otherwise confidential information. Successful exploits may facilitate a compromise of the underlying computer.
Version 4.0 of Easy File Sharing Web Server is vulnerable; other versions may also be affected.
Exploit / POC
Easy File Sharing Web Server Information Disclosure and Input Validation Vulnerabilities
Attackers can use a web client to exploit these issues.
An alternative file streams proof-of-concpet exploit is included as well.
Attackers can use a web client to exploit these issues.
An alternative file streams proof-of-concpet exploit is included as well.
Solution / Fix
Easy File Sharing Web Server Information Disclosure and Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Easy File Sharing Web Server Information Disclosure and Input Validation Vulnerabilities
References:
References:
- Easy File Sharing Web Server (EFS Software)