Apple Mac OS X Server Wiki Server Directory Traversal Vulnerability
BID:28278
Info
Apple Mac OS X Server Wiki Server Directory Traversal Vulnerability
| Bugtraq ID: | 28278 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1000 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2008 12:00AM |
| Updated: | Mar 19 2008 02:40AM |
| Credit: | Rodrigo Carvalho from the Core Security Consulting Services (CSC) team of Core Security Technologies. |
| Vulnerable: |
Apple Wiki Server 10.5 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.2 |
| Not Vulnerable: | |
Discussion
Apple Mac OS X Server Wiki Server Directory Traversal Vulnerability
Apple Mac OS X Server Wiki Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to access arbitrary files outside of the application's document root directory. This can expose sensitive information that could help the attacker launch further attacks.
Note that attackers must be registered wiki users to exploit this issue.
Wiki Server from Mac OS X Server 10.5 is vulnerable.
Apple Mac OS X Server Wiki Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to access arbitrary files outside of the application's document root directory. This can expose sensitive information that could help the attacker launch further attacks.
Note that attackers must be registered wiki users to exploit this issue.
Wiki Server from Mac OS X Server 10.5 is vulnerable.
Exploit / POC
Apple Mac OS X Server Wiki Server Directory Traversal Vulnerability
Attackers can use a browser to exploit this issue.
The following proof-of-concept example is available:
Attackers can use a browser to exploit this issue.
The following proof-of-concept example is available:
Solution / Fix
Apple Mac OS X Server Wiki Server Directory Traversal Vulnerability
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Apple Mac OS X 10.5.2
Apple Mac OS X Server 10.5.2
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Apple Mac OS X 10.5.2
-
Apple SecUpd2008-002.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002.dmg
Apple Mac OS X Server 10.5.2
References
Apple Mac OS X Server Wiki Server Directory Traversal Vulnerability
References:
References:
- Mac OS X Server Homepage (Apple)
- Mac OS X Server Wiki Server Homepage (Apple)
- CORE-2008-0123: Leopard Server Remote Path Traversal (Core Security Technologies Advisories
) - CORE-2008-0123 Leopard Server Remote Path Traversal (Core Security Technologies )