Easy File Sharing Web Server Directory Traversal and Multiple Information Disclosure Vulnerabilities
BID:26771
Info
Easy File Sharing Web Server Directory Traversal and Multiple Information Disclosure Vulnerabilities
| Bugtraq ID: | 26771 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 07 2007 12:00AM |
| Updated: | Dec 10 2007 11:22PM |
| Credit: | Luigi Auriemma is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
SHTTPD SHTTPD 1.38 SHTTPD SHTTPD 1.35 SHTTPD SHTTPD 1.34 |
| Not Vulnerable: | |
Discussion
Easy File Sharing Web Server Directory Traversal and Multiple Information Disclosure Vulnerabilities
Easy File Sharing Web Server is prone to a directory-traversal and multiple information-disclosure vulnerabilities.
Successfully exploiting these issues allows remote attackers to upload files to arbitrary locations and to access potentially sensitive information, which may aid in further attacks.
Easy File Sharing Web Server 4.5 is vulnerable to these issues; other versions may also be affected.
Easy File Sharing Web Server is prone to a directory-traversal and multiple information-disclosure vulnerabilities.
Successfully exploiting these issues allows remote attackers to upload files to arbitrary locations and to access potentially sensitive information, which may aid in further attacks.
Easy File Sharing Web Server 4.5 is vulnerable to these issues; other versions may also be affected.
Exploit / POC
Easy File Sharing Web Server Directory Traversal and Multiple Information Disclosure Vulnerabilities
Attackers may exploit these issues through a browser.
The following exploit is available:
Attackers may exploit these issues through a browser.
The following exploit is available:
Solution / Fix
Easy File Sharing Web Server Directory Traversal and Multiple Information Disclosure Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Easy File Sharing Web Server Directory Traversal and Multiple Information Disclosure Vulnerabilities
References:
References:
- Easy File Sharing Web Server (EFS Software)
- Upload directory traversal in Easy File Sharing 4.5 (Luigi Auriemma
)