Steve Grimm Un-CGI Directory Traversal Vulnerability
BID:3056
Info
Steve Grimm Un-CGI Directory Traversal Vulnerability
| Bugtraq ID: | 3056 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1242 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | This vulnerability was discovered by Khamba Staring <[email protected]> and submitted to BugTraq on July 17th, 2001. |
| Vulnerable: |
Steve Grimm Un-CGI 1.9 Steve Grimm Un-CGI 1.8 Steve Grimm Un-CGI 1.7 Steve Grimm Un-CGI 1.6.2 Steve Grimm Un-CGI 1.6 Steve Grimm Un-CGI 1.5 Steve Grimm Un-CGI 1.4 Steve Grimm Un-CGI 1.3 Steve Grimm Un-CGI 1.2 Steve Grimm Un-CGI 1.1 Steve Grimm Un-CGI 1.0 |
| Not Vulnerable: |
Steve Grimm Un-CGI 1.10 |
Discussion
Steve Grimm Un-CGI Directory Traversal Vulnerability
Un-CGI is a free CGI Wrapper application. Its function is to parse URL encoded input and translate it for use by CGI applications. It may be used as a library or as a stand-alone executable.
A problem exists with the Un-CGI executable. It does not filter '../' sequences from user-supplied input. Thus it is possible to access arbitrary web-readable files on the host, which may disclose sensitive information to remote attackers.
It is also possible to use this vulnerability to remotely execute other scripts located on the host.
Un-CGI is a free CGI Wrapper application. Its function is to parse URL encoded input and translate it for use by CGI applications. It may be used as a library or as a stand-alone executable.
A problem exists with the Un-CGI executable. It does not filter '../' sequences from user-supplied input. Thus it is possible to access arbitrary web-readable files on the host, which may disclose sensitive information to remote attackers.
It is also possible to use this vulnerability to remotely execute other scripts located on the host.
Solution / Fix
Steve Grimm Un-CGI Directory Traversal Vulnerability
Solution:
The vendor has released a fixed version which addresses this issue.
Solution:
The vendor has released a fixed version which addresses this issue.