SeaGlass Technologies sglMerchant Directory Traversal Vulnerability
BID:3309
Info
SeaGlass Technologies sglMerchant Directory Traversal Vulnerability
| Bugtraq ID: | 3309 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1019 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was submitted to BugTraq on September 8th, 2001 by Alexey Sintsov <[email protected]>. |
| Vulnerable: |
SeaGlass Technologies Inc sglMerchant 1.0 |
| Not Vulnerable: | |
Discussion
SeaGlass Technologies sglMerchant Directory Traversal Vulnerability
sglMerchant is a web-commerce application.
sglMerchant does not adequately filter user-supplied input in the form of '../' sequences. It is possible for a remote attacker to construct a web request which will break out of wwwroot to browse the filesystem of the host. The attacker may exploit this issue to display arbitrary web-readable files.
The sensitive information contained in disclosed files may aid the attacker in making further, more educated attempts at fully compromising the host.
sglMerchant is a web-commerce application.
sglMerchant does not adequately filter user-supplied input in the form of '../' sequences. It is possible for a remote attacker to construct a web request which will break out of wwwroot to browse the filesystem of the host. The attacker may exploit this issue to display arbitrary web-readable files.
The sensitive information contained in disclosed files may aid the attacker in making further, more educated attempts at fully compromising the host.
Exploit / POC
SeaGlass Technologies sglMerchant Directory Traversal Vulnerability
This issue can be exploited with a web browser.
This issue can be exploited with a web browser.
Solution / Fix
SeaGlass Technologies sglMerchant Directory Traversal Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SeaGlass Technologies sglMerchant Directory Traversal Vulnerability
References:
References: