IBM HTTP Server Source Code Disclosure Vulnerability
BID:3518
Info
IBM HTTP Server Source Code Disclosure Vulnerability
| Bugtraq ID: | 3518 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2001 12:00AM |
| Updated: | Nov 08 2001 12:00AM |
| Credit: | This vulnerability was discovered by "'ken'@FTU" <[email protected]> and posted to BugTraq on November 8th, 2001. |
| Vulnerable: |
IBM HTTP Server 1.3.19 IBM HTTP Server 1.3.12 .4 IBM HTTP Server 1.3.12 .3 IBM HTTP Server 1.3.12 .2 IBM HTTP Server 1.3.6 win32 IBM HTTP Server 1.3.6 .4 win32 IBM HTTP Server 1.3.6 .3 IBM HTTP Server 1.3.6 .2 win32 IBM HTTP Server 1.3.6 .2 unix IBM HTTP Server 1.3.3 win32 |
| Not Vulnerable: | |
Discussion
IBM HTTP Server Source Code Disclosure Vulnerability
Due to an input validation error in IBM HTTP Server for the AS/400, it is possible for a remote attacker to make a specially web crafted web request which will display script source code.
If a '/' is appended to the end of a request for an existing script, then this will cause the script's source code to be displayed.
There is a potential that this issue may result in sensitive information being disclosed to attackers, depending on the contents of the script source code.
*It has been reported that the source of this issue is due to WebSphere Application server 3.5.4. However this has not yet been confirmed by the vendor.
Due to an input validation error in IBM HTTP Server for the AS/400, it is possible for a remote attacker to make a specially web crafted web request which will display script source code.
If a '/' is appended to the end of a request for an existing script, then this will cause the script's source code to be displayed.
There is a potential that this issue may result in sensitive information being disclosed to attackers, depending on the contents of the script source code.
*It has been reported that the source of this issue is due to WebSphere Application server 3.5.4. However this has not yet been confirmed by the vendor.
Solution / Fix
IBM HTTP Server Source Code Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.