GeekiGeeki Multiple File Disclosure Vulnerabilities
BID:32831
Info
GeekiGeeki Multiple File Disclosure Vulnerabilities
| Bugtraq ID: | 32831 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2008 12:00AM |
| Updated: | Dec 19 2008 02:31PM |
| Credit: | These issues were reported by the vendor. |
| Vulnerable: |
Bernie Innocenti GeekiGeeki 2.0 |
| Not Vulnerable: |
Bernie Innocenti GeekiGeeki 3.0 |
Discussion
GeekiGeeki Multiple File Disclosure Vulnerabilities
GeekiGeeki is prone to multiple file-disclosure vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to view local files in the context of the webserver process. This may aid in further attacks.
Versions prior to GeekiGeeki 3.0 are affected.
GeekiGeeki is prone to multiple file-disclosure vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to view local files in the context of the webserver process. This may aid in further attacks.
Versions prior to GeekiGeeki 3.0 are affected.
Exploit / POC
GeekiGeeki Multiple File Disclosure Vulnerabilities
Attackers can exploit these issues via a browser.
Attackers can exploit these issues via a browser.
Solution / Fix
GeekiGeeki Multiple File Disclosure Vulnerabilities
Solution:
The vendor has released GeekiGeeki 3.0 to address these issues. Please see the references for more information.
Bernie Innocenti GeekiGeeki 2.0
Solution:
The vendor has released GeekiGeeki 3.0 to address these issues. Please see the references for more information.
Bernie Innocenti GeekiGeeki 2.0
-
Bernie Innocenti geekigeeki-3.0.tar.gz
http://www.codewiz.org/wikigit/geekigeeki.git?a=snapshot;h=v3.0;sf=tbz 2
References
GeekiGeeki Multiple File Disclosure Vulnerabilities
References:
References:
- GeekiGeeki Homepage (Bernie Innocenti)