MIMAnet Source Viewer Directory Traversal Vulnerability
BID:2762
Info
MIMAnet Source Viewer Directory Traversal Vulnerability
| Bugtraq ID: | 2762 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 23 2001 12:00AM |
| Updated: | May 23 2001 12:00AM |
| Credit: | This vulnerability was posted to BugTraq on May 23rd, 2001 by <[email protected]>. |
| Vulnerable: |
MIMAnet Source Viewer 2.0 |
| Not Vulnerable: | |
Discussion
MIMAnet Source Viewer Directory Traversal Vulnerability
MIMAnet Source Viewer is a freely available CGI script which allows users to view the source code of files located elsewhere on the server.
Source Viewer accepts an argument, 'loc', which it uses as the filename when opening the requested file. Unfortunately it does not filter '..' and '/' characters, which can be misinterpreted by the script and cause files outside of the intended directory to be opened. As a result, it may be possible for attackers to view the contents of arbitrary webserver-readable files on the filesystem.
MIMAnet Source Viewer is a freely available CGI script which allows users to view the source code of files located elsewhere on the server.
Source Viewer accepts an argument, 'loc', which it uses as the filename when opening the requested file. Unfortunately it does not filter '..' and '/' characters, which can be misinterpreted by the script and cause files outside of the intended directory to be opened. As a result, it may be possible for attackers to view the contents of arbitrary webserver-readable files on the filesystem.
References
MIMAnet Source Viewer Directory Traversal Vulnerability
References:
References: