DataWizard WebXQ Directory Traversal Vulnerability
BID:2660
Info
DataWizard WebXQ Directory Traversal Vulnerability
| Bugtraq ID: | 2660 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 27 2001 12:00AM |
| Updated: | Apr 27 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by <[email protected]> on April 27, 2001. |
| Vulnerable: |
DataWizard WebXQ 2.1.204 |
| Not Vulnerable: |
DataWizard WebXQ 2.1.205 |
Discussion
DataWizard WebXQ Directory Traversal Vulnerability
DataWizard WebXQ server could be led to traverse directories and possibly reveal files outside of the web root.
By including '/../' sequences along with a known file or directory in requested URLs, a remote user can obtain read access to the requested directories and files outside the web root, potentially compromising the privacy of user data and/or obtaining information which could be used to further compromise the host.
DataWizard WebXQ server could be led to traverse directories and possibly reveal files outside of the web root.
By including '/../' sequences along with a known file or directory in requested URLs, a remote user can obtain read access to the requested directories and files outside the web root, potentially compromising the privacy of user data and/or obtaining information which could be used to further compromise the host.
Solution / Fix
DataWizard WebXQ Directory Traversal Vulnerability
Solution:
DataWizard has addressed this issue in WebXQ 2.1.205:
http://www.datawizard.net/Free_Software/WebXQ_Free/webxq_free.htm
Solution:
DataWizard has addressed this issue in WebXQ 2.1.205:
http://www.datawizard.net/Free_Software/WebXQ_Free/webxq_free.htm