MyServer Filename Parse Error Information Disclosure Vulnerability
BID:24571
Info
MyServer Filename Parse Error Information Disclosure Vulnerability
| Bugtraq ID: | 24571 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3365 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Shay Priel is credited with the discovery of this vulnerability. |
| Vulnerable: |
myServer myServer 0.8.9 |
| Not Vulnerable: | |
Discussion
MyServer Filename Parse Error Information Disclosure Vulnerability
MyServer is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to access sensitive information that may lead to further attacks.
This issue affects MyServer 0.8.9; other versions may also be affected.
MyServer is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to access sensitive information that may lead to further attacks.
This issue affects MyServer 0.8.9; other versions may also be affected.
Exploit / POC
MyServer Filename Parse Error Information Disclosure Vulnerability
An attacker can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/cgi-bin/post.mscgI (Note: Capital 'I' at the end of the URI)
An attacker can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/cgi-bin/post.mscgI (Note: Capital 'I' at the end of the URI)
Solution / Fix
MyServer Filename Parse Error Information Disclosure Vulnerability
Solution:
Currently we are not aware of any solutions for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any solutions for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
MyServer Filename Parse Error Information Disclosure Vulnerability
References:
References:
- Vendor Homepage (MyServer)
- MyServer-0.8.9 - source code disclosure (Shay Priel)