Martin Hamilton ROADS File Disclosure Vulnerability
BID:2371
Info
Martin Hamilton ROADS File Disclosure Vulnerability
| Bugtraq ID: | 2371 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 12 2001 12:00AM |
| Updated: | Feb 12 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by <[email protected]> on Feb 12, 2001. |
| Vulnerable: |
Martin Hamilton ROADS 2.3 |
| Not Vulnerable: |
Martin Hamilton ROADS 2.4 |
Discussion
Martin Hamilton ROADS File Disclosure Vulnerability
A remote user could gain read access to known files outside of the root directory where Martin Hamilton ROADS resides. Requesting a specially crafted URL composed of '%00' sequences along with the known filename will disclose the requested file.
A remote user could gain read access to known files outside of the root directory where Martin Hamilton ROADS resides. Requesting a specially crafted URL composed of '%00' sequences along with the known filename will disclose the requested file.
Solution / Fix
Martin Hamilton ROADS File Disclosure Vulnerability
Solution:
Martin Hamilton has addressed this issue in ROADS 2.4 and has also released a patch for ROADS 2.3:
Martin Hamilton ROADS 2.3
Solution:
Martin Hamilton has addressed this issue in ROADS 2.4 and has also released a patch for ROADS 2.3:
Martin Hamilton ROADS 2.3
-
Martin Hamilton patch-v2.3-1
ftp://ftp.roads.lut.ac.uk/roads/patch-v2.3-1 -
Martin Hamilton roads-v2.4.tar.gz
ftp://ftp.roads.lut.ac.uk/roads/roads-v2.4.tar.gz