Xcache Path Disclosure Vulnerability
BID:3352
Info
Xcache Path Disclosure Vulnerability
| Bugtraq ID: | 3352 |
| Class: | Design Error |
| CVE: |
CVE-2001-1023 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was posted to BugTraq by [email protected]. |
| Vulnerable: |
Xcache Technologies Xcache 2.1 Xcache Technologies Xcache 2.0 |
| Not Vulnerable: | |
Discussion
Xcache Path Disclosure Vulnerability
Xcache is a dynamic content caching application which runs in conjunction with Microsoft Internet Information Server. Xcache allows for individual pages or entire folders to have caching disabled if necessary.
When a request is made for a page or a page within a folder that is not cached, Xcache returns the full path to the page within the HTTP header information. This path information will be returned regardless of where the page resides on the server.
This information could potentially be used by an attacker to mount an attack upon the target webserver.
Xcache is a dynamic content caching application which runs in conjunction with Microsoft Internet Information Server. Xcache allows for individual pages or entire folders to have caching disabled if necessary.
When a request is made for a page or a page within a folder that is not cached, Xcache returns the full path to the page within the HTTP header information. This path information will be returned regardless of where the page resides on the server.
This information could potentially be used by an attacker to mount an attack upon the target webserver.
Exploit / POC
Xcache Path Disclosure Vulnerability
There is no exploit code necessary for this vulnerability.
There is no exploit code necessary for this vulnerability.
Solution / Fix
Xcache Path Disclosure Vulnerability
Solution:
Xcache Technologies has produced a patch to address this issue, however, it is not available for public download.
Users of Xcache can obtain the patch by contacting [email protected].
Solution:
Xcache Technologies has produced a patch to address this issue, however, it is not available for public download.
Users of Xcache can obtain the patch by contacting [email protected].