Last Lines CGI Script Directory Traversal Vulnerability
BID:3754
Info
Last Lines CGI Script Directory Traversal Vulnerability
| Bugtraq ID: | 3754 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1205 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 30 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | This vulnerability was submitted to BugTraq on December 30th, 2001 by "BrainRawt ." <[email protected]>. |
| Vulnerable: |
Matrix's CGI vault Last Lines 2.0 |
| Not Vulnerable: | |
Discussion
Last Lines CGI Script Directory Traversal Vulnerability
Last Lines CGI is a freely available script written in Perl and maintained by the Matrix's CGI Vault. It allows the user to print a specified number of lines from a log file(or any text file) to a webpage. It can run on Linux and Unix systems or any other platform with Apache and Perl support.
Lastlines.cgi is prone to directory traversal attacks. It is possible for a remote attacker to submit a maliciously crafted web request which is capable of breaking out of wwwroot and browsing arbitrary web-readable files on a host running the vulnerable script.
Last Lines CGI is a freely available script written in Perl and maintained by the Matrix's CGI Vault. It allows the user to print a specified number of lines from a log file(or any text file) to a webpage. It can run on Linux and Unix systems or any other platform with Apache and Perl support.
Lastlines.cgi is prone to directory traversal attacks. It is possible for a remote attacker to submit a maliciously crafted web request which is capable of breaking out of wwwroot and browsing arbitrary web-readable files on a host running the vulnerable script.
Exploit / POC
Last Lines CGI Script Directory Traversal Vulnerability
This vulnerability can be exploited with a web browser.
This vulnerability can be exploited with a web browser.
Solution / Fix
Last Lines CGI Script Directory Traversal Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Last Lines CGI Script Directory Traversal Vulnerability
References:
References:
- Last Lines Homepage (Matrix's CGI Vault)