iWeb Server URL Directory Traversal Vulnerability
BID:37228
Info
iWeb Server URL Directory Traversal Vulnerability
| Bugtraq ID: | 37228 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4053 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 07 2009 12:00AM |
| Updated: | Dec 09 2009 04:04PM |
| Credit: | mr_me |
| Vulnerable: |
Ashley Brown iWeb Server 0 |
| Not Vulnerable: | |
Discussion
iWeb Server URL Directory Traversal Vulnerability
iWeb Server is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue allows an attacker to access files outside of the webserver's root directory. Successful exploits will allow the attacker to obtain sensitive information.
iWeb Server is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue allows an attacker to access files outside of the webserver's root directory. Successful exploits will allow the attacker to obtain sensitive information.
Exploit / POC
iWeb Server URL Directory Traversal Vulnerability
An attacker can exploit this issue through a browser.
The following example URI is available:
http://www.example.com/..%5C..%5C..%5Cboot.ini
An attacker can exploit this issue through a browser.
The following example URI is available:
http://www.example.com/..%5C..%5C..%5Cboot.ini
Solution / Fix
iWeb Server URL Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].