IBM Informix Web Datablade Directory Traversal Vulnerability
BID:3575
Info
IBM Informix Web Datablade Directory Traversal Vulnerability
| Bugtraq ID: | 3575 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0924 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 22 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | This vulnerability was submitted to BugTraq on November 22nd, 2001 by Beck Mr.R <[email protected]>. |
| Vulnerable: |
IBM Informix Web Datablade 4.12 IBM Informix Web Datablade 4.11 IBM Informix Web Datablade 4.10 IBM Informix Web Datablade 3.7 IBM Informix Web Datablade 3.6 IBM Informix Web Datablade 3.5 IBM Informix Web Datablade 3.4 IBM Informix Web Datablade 3.3 |
| Not Vulnerable: |
IBM Informix Web Datablade 4.13 |
Discussion
IBM Informix Web Datablade Directory Traversal Vulnerability
Informix is an enterprise database distributed and maintained by IBM. The Web Datablade Module for Informix SQL is used to provide wbBinaries for storing large binary resources such as images, sounds, etc.
The Web Datablade Module for Informix SQL is prone to a directory traversal vulnerability. A remote attacker who submits a specially crafted web request containing dot-dot-slash(../) sequences may be able to break out of wwwroot and browse arbitrary web-readable files on a vulnerable host.
This issue is known to occur when large object caching is enabled, which sets cache_directory as a web driver variable. It occurs independently of the web server that is being used.
As a result, sensitive information disclosed in arbitrary web-readable files may be used by the remote attacker to make more concentrated attacks in an attempt to further compromise the host.
Informix is an enterprise database distributed and maintained by IBM. The Web Datablade Module for Informix SQL is used to provide wbBinaries for storing large binary resources such as images, sounds, etc.
The Web Datablade Module for Informix SQL is prone to a directory traversal vulnerability. A remote attacker who submits a specially crafted web request containing dot-dot-slash(../) sequences may be able to break out of wwwroot and browse arbitrary web-readable files on a vulnerable host.
This issue is known to occur when large object caching is enabled, which sets cache_directory as a web driver variable. It occurs independently of the web server that is being used.
As a result, sensitive information disclosed in arbitrary web-readable files may be used by the remote attacker to make more concentrated attacks in an attempt to further compromise the host.
Exploit / POC
IBM Informix Web Datablade Directory Traversal Vulnerability
Beck Mr.R <[email protected]> provided the following example:
http://site.com/ifx/?LO=../../../file
Beck Mr.R <[email protected]> provided the following example:
http://site.com/ifx/?LO=../../../file
Solution / Fix
IBM Informix Web Datablade Directory Traversal Vulnerability
Solution:
The vendor has addressed this in IBM Informix Web Datablade version
4.13. Users are advised to upgrade to 4.13. Additional information may be available at IBM Informix Technical Support, which may be reached at the following URL:
http://www-4.ibm.com/software/data/informix/support/
Users may also contact their local sales office for additional details.
Solution:
The vendor has addressed this in IBM Informix Web Datablade version
4.13. Users are advised to upgrade to 4.13. Additional information may be available at IBM Informix Technical Support, which may be reached at the following URL:
http://www-4.ibm.com/software/data/informix/support/
Users may also contact their local sales office for additional details.