Acme.Serve v1.7 Arbitrary File Access Vulnerability
BID:2809
Info
Acme.Serve v1.7 Arbitrary File Access Vulnerability
| Bugtraq ID: | 2809 |
| Class: | Design Error |
| CVE: |
CVE-2001-0748 |
| Remote: | Yes |
| Local: | No |
| Published: | May 31 2001 12:00AM |
| Updated: | Mar 19 2015 08:37AM |
| Credit: | This was posted to BugTraq by "Adnan Rahman" <[email protected]> on May 31st, 2001. |
| Vulnerable: |
APC PowerChute Network Shutdown 2.2.1 ACME Laboratories Acme.Serve 1.7 |
| Not Vulnerable: | |
Discussion
Acme.Serve v1.7 Arbitrary File Access Vulnerability
Acme.Serve is a free, open-source, embeddable webserver written in Java. It is small, is intended to provide minimal functionality, and is fully compatible with JavaServer.
Acme.Serve 1.7 comes with a webserver that listens on port 9090. This webserver allows clients to browse the filesystem. By default, this webserver is enabled and accessible by any remote host on the Internet.
If an attacker were to connect, they could view possibly sensitive information.
Acme.Serve is a free, open-source, embeddable webserver written in Java. It is small, is intended to provide minimal functionality, and is fully compatible with JavaServer.
Acme.Serve 1.7 comes with a webserver that listens on port 9090. This webserver allows clients to browse the filesystem. By default, this webserver is enabled and accessible by any remote host on the Internet.
If an attacker were to connect, they could view possibly sensitive information.
Exploit / POC
Acme.Serve v1.7 Arbitrary File Access Vulnerability
The following example has been provided:
http://potentialvictim:9090//etc/shadow to view '/etc/shadow'.
The following example has been provided:
http://potentialvictim:9090//etc/shadow to view '/etc/shadow'.
Solution / Fix
Acme.Serve v1.7 Arbitrary File Access Vulnerability
Solution:
Cisco has released version 2.3.6.1 of Secure ACS for UNIX, which resolves this issue. Customers are advised to obtain an update through their regular update channels.
Cisco Secure ACS for Unix 2.0
Cisco Secure ACS for Unix 2.3
Cisco Secure ACS for Unix 2.3.5 .1
Solution:
Cisco has released version 2.3.6.1 of Secure ACS for UNIX, which resolves this issue. Customers are advised to obtain an update through their regular update channels.
Cisco Secure ACS for Unix 2.0
-
Cisco Secure ACS for Unix 2.3.6.1
http://www.cisco.com/pcgi-bin/tablebuild.pl/cs-acs
Cisco Secure ACS for Unix 2.3
-
Cisco Secure ACS for Unix 2.3.6.1
http://www.cisco.com/pcgi-bin/tablebuild.pl/cs-acs
Cisco Secure ACS for Unix 2.3.5 .1
-
Cisco Secure ACS for Unix 2.3.6.1
http://www.cisco.com/pcgi-bin/tablebuild.pl/cs-acs
References
Acme.Serve v1.7 Arbitrary File Access Vulnerability
References:
References:
- Acme.Serve Package Page (ACME Laboratories)
- APC PowerChute Network Shutdown 2.21 is vulnerable to directory transversal (guiness.stout)
- Vendor Homepage (APC)