Radware AppWall Source Code Information Disclosure Vulnerability
BID:35551
Info
Radware AppWall Source Code Information Disclosure Vulnerability
| Bugtraq ID: | 35551 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 01 2009 12:00AM |
| Updated: | Jul 08 2009 03:06PM |
| Credit: | Michael Kirchner, Wolfgang Neudorfer, Lukas Nothdurfter (Team h4ck!nb3rg) |
| Vulnerable: |
Radware Gateway 4.6 .2 Radware AppWall 1.0.2 6 |
| Not Vulnerable: | |
Discussion
Radware AppWall Source Code Information Disclosure Vulnerability
Radware AppWall is prone to a vulnerability that lets attackers access certain sourcecode files.
An attacker can exploit this vulnerability to retrieve certain files from the vulnerable computer in the context of the webserver process. Information obtained may aid in further attacks.
The issue affects the following:
AppWall 1.0.2.6
Gateway 4.6.0.2
Other versions may be affected as well.
Radware AppWall is prone to a vulnerability that lets attackers access certain sourcecode files.
An attacker can exploit this vulnerability to retrieve certain files from the vulnerable computer in the context of the webserver process. Information obtained may aid in further attacks.
The issue affects the following:
AppWall 1.0.2.6
Gateway 4.6.0.2
Other versions may be affected as well.
Exploit / POC
Radware AppWall Source Code Information Disclosure Vulnerability
Attackers can exploit this vulnerability via a browser.
Attackers can exploit this vulnerability via a browser.
Solution / Fix
Radware AppWall Source Code Information Disclosure Vulnerability
Solution:
The vendor indicates that this issue will be addressed in an upcoming release.
Solution:
The vendor indicates that this issue will be addressed in an upcoming release.
References
Radware AppWall Source Code Information Disclosure Vulnerability
References:
References:
- AppWall Homepage (Radware)
- radware AppWall Web Application Firewall Vulnerability (Team h4ck!nb3rg)