AOLserver Directory Traversal Vulnerability
BID:2343
Info
AOLserver Directory Traversal Vulnerability
| Bugtraq ID: | 2343 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0205 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 06 2001 12:00AM |
| Updated: | Jul 11 2009 04:46AM |
| Credit: | Discovered and posted to Bugtraq by <[email protected]> on Feb 6, 2001. |
| Vulnerable: |
AOL AOLserver 3.2 Win32 |
| Not Vulnerable: |
AOL AOLserver 3.4 Win32 AOL AOLserver 3.3 Win32 |
Discussion
AOLserver Directory Traversal Vulnerability
It is possible for a remote user to gain read access to directories outside the root directory of an AOLserver. Requesting a specially crafted URL composed of '.../' sequences will disclose an arbitrary directory.
It is possible for a remote user to gain read access to directories outside the root directory of an AOLserver. Requesting a specially crafted URL composed of '.../' sequences will disclose an arbitrary directory.
Exploit / POC
AOLserver Directory Traversal Vulnerability
The following example has been provided by <[email protected]>:
http://target/.../[file outside web root]
The following example has been provided by <[email protected]>:
http://target/.../[file outside web root]
Solution / Fix
AOLserver Directory Traversal Vulnerability
Solution:
Fixed version available:
Solution:
Fixed version available: