BRS WebWeaver Directory Traversal Vulnerability
BID:2675
Info
BRS WebWeaver Directory Traversal Vulnerability
| Bugtraq ID: | 2675 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0453 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 28 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | (courtesy [email protected]): Solution: The web server root traversal vulnerabilities can be prevented by removing all user-defined aliases (ie: 'syshelp', 'sysimages') as well as the ISAPI/CGI alias (ie: 'scripts'). |
| Vulnerable: |
BRS WebWeaver 0.62 beta BRS WebWeaver 0.61 beta BRS WebWeaver 0.60 beta BRS WebWeaver 0.52 beta BRS WebWeaver 0.51 beta BRS WebWeaver 0.50 beta BRS WebWeaver 0.49 beta |
| Not Vulnerable: |
BRS WebWeaver 0.63 beta |
Discussion
BRS WebWeaver Directory Traversal Vulnerability
BRS WebWeaver is an FTPD and webserver by Blaine Southam.
WebWeaver is vulnerable to directory traversal techniques, by which a remote user may request and obtain files from outside the web root.
By submitting a properly-formatted URL to the webserver which includes '..' sequences (specifying a relative path), an attacker can traverse the webserver's directory structure and request files from outside the web root.
Properly exploited, this could permit an attacker to obtain private user data, or sensitive system-related information which could be used to further undermine system security.
BRS WebWeaver is an FTPD and webserver by Blaine Southam.
WebWeaver is vulnerable to directory traversal techniques, by which a remote user may request and obtain files from outside the web root.
By submitting a properly-formatted URL to the webserver which includes '..' sequences (specifying a relative path), an attacker can traverse the webserver's directory structure and request files from outside the web root.
Properly exploited, this could permit an attacker to obtain private user data, or sensitive system-related information which could be used to further undermine system security.
Exploit / POC
BRS WebWeaver Directory Traversal Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
BRS WebWeaver Directory Traversal Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
BRS WebWeaver 0.49 beta
BRS WebWeaver 0.50 beta
BRS WebWeaver 0.51 beta
BRS WebWeaver 0.52 beta
BRS WebWeaver 0.60 beta
BRS WebWeaver 0.61 beta
BRS WebWeaver 0.62 beta
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
BRS WebWeaver 0.49 beta
-
BRS 0.63 beta WebWeaver063.exe
http://members.nbci.com/_XMCM/BSoutham/download/WebWeaver063.exe
BRS WebWeaver 0.50 beta
-
BRS 0.63 beta WebWeaver063.exe
http://members.nbci.com/_XMCM/BSoutham/download/WebWeaver063.exe
BRS WebWeaver 0.51 beta
-
BRS 0.63 beta WebWeaver063.exe
http://members.nbci.com/_XMCM/BSoutham/download/WebWeaver063.exe
BRS WebWeaver 0.52 beta
-
BRS 0.63 beta WebWeaver063.exe
http://members.nbci.com/_XMCM/BSoutham/download/WebWeaver063.exe
BRS WebWeaver 0.60 beta
-
BRS 0.63 beta WebWeaver063.exe
http://members.nbci.com/_XMCM/BSoutham/download/WebWeaver063.exe
BRS WebWeaver 0.61 beta
-
BRS 0.63 beta WebWeaver063.exe
http://members.nbci.com/_XMCM/BSoutham/download/WebWeaver063.exe
BRS WebWeaver 0.62 beta
-
BRS 0.63 beta WebWeaver063.exe
http://members.nbci.com/_XMCM/BSoutham/download/WebWeaver063.exe