H-Sphere Arbitrary File Disclosure Vulnerability
BID:3359
Info
H-Sphere Arbitrary File Disclosure Vulnerability
| Bugtraq ID: | 3359 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2001 12:00AM |
| Updated: | Sep 25 2001 12:00AM |
| Credit: | This vulnerability was published on September 25th, 2001 by Crazy Einstein <[email protected]>. |
| Vulnerable: |
Positive Software Corporation H-Sphere 2.0 5 Positive Software Corporation H-Sphere 2.0 Positive Software Corporation H-Sphere 1.5 |
| Not Vulnerable: |
Positive Software Corporation H-Sphere 2.0 6 |
Discussion
H-Sphere Arbitrary File Disclosure Vulnerability
H-Sphere provides automation for web hosting across multiple servers. It is a commercial product that will run on Linux, FreeBSD and Microsoft Windows 2000. It supports both Apache and IIS webservers.
H-Sphere does not filter '../' sequences from some requests, which has the potential to disclose sensitive information. A malicious user may make a specially crafted web request which will allow them to break out of wwwroot and browse the filesystem at large. Arbitrary web-readable files may be displayed by the attacker using this attack.
To successfully exploit this issue, the malicious user must have access to an account for a hosted website.
H-Sphere provides automation for web hosting across multiple servers. It is a commercial product that will run on Linux, FreeBSD and Microsoft Windows 2000. It supports both Apache and IIS webservers.
H-Sphere does not filter '../' sequences from some requests, which has the potential to disclose sensitive information. A malicious user may make a specially crafted web request which will allow them to break out of wwwroot and browse the filesystem at large. Arbitrary web-readable files may be displayed by the attacker using this attack.
To successfully exploit this issue, the malicious user must have access to an account for a hosted website.
Exploit / POC
H-Sphere Arbitrary File Disclosure Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
H-Sphere Arbitrary File Disclosure Vulnerability
Solution:
This issue has been addressed in H-Sphere v2.06 and later. Users are advised to upgrade.
Solution:
This issue has been addressed in H-Sphere v2.06 and later. Users are advised to upgrade.
References
H-Sphere Arbitrary File Disclosure Vulnerability
References:
References:
- Positive Software Homepage (Positive Software)