NaviCOPA Source Code Information Disclosure Vulnerability
BID:36705
Info
NaviCOPA Source Code Information Disclosure Vulnerability
| Bugtraq ID: | 36705 |
| Class: | Design Error |
| CVE: |
CVE-2009-4529 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 14 2009 12:00AM |
| Updated: | Apr 13 2015 09:06PM |
| Credit: | Dr_IDE |
| Vulnerable: |
Intervations NaviCOPA Web Server 3.0.1 .2 |
| Not Vulnerable: | |
Discussion
NaviCOPA Source Code Information Disclosure Vulnerability
NaviCOPA is prone to a vulnerability that lets attackers access certain sourcecode files.
An attacker can exploit this vulnerability to retrieve certain files from the vulnerable computer in the context of the webserver process. Information obtained may aid in further attacks.
The issue affects NaviCOPA 3.0.1.2 and prior versions.
NaviCOPA is prone to a vulnerability that lets attackers access certain sourcecode files.
An attacker can exploit this vulnerability to retrieve certain files from the vulnerable computer in the context of the webserver process. Information obtained may aid in further attacks.
The issue affects NaviCOPA 3.0.1.2 and prior versions.
Exploit / POC
NaviCOPA Source Code Information Disclosure Vulnerability
Attackers can exploit this vulnerability via a browser.
The following example URIs are available:
http://www.example.com/index.html%20
http://www.example.com/index.php%20
Attackers can exploit this vulnerability via a browser.
The following example URIs are available:
http://www.example.com/index.html%20
http://www.example.com/index.php%20
Solution / Fix
NaviCOPA Source Code Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
NaviCOPA Source Code Information Disclosure Vulnerability
References:
References:
- NaviCOPA Homepage (Intervations)
- NaviCOPA Web Server <= 3.0.1.2 Remote Source Disclosure (Dr_IDE)