AOLServer Password Protected File Arbitrary Read Access Vulnerability
BID:3791
Info
AOLServer Password Protected File Arbitrary Read Access Vulnerability
| Bugtraq ID: | 3791 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-0100 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | This vulnerability was announced by Tamer Sahin <[email protected]> via Bugtraq on January 6, 2002. |
| Vulnerable: |
AOL AOLserver 3.4.2 Win32 |
| Not Vulnerable: |
AOL AOLserver 3.4.2 |
Discussion
AOLServer Password Protected File Arbitrary Read Access Vulnerability
AOLServer is the open source, freely available HTTP server maintained in cooperation between AOL and the open source developer community. It offers features such as TCL interpretation, and dynamic content handling.
A problem has been discovered in AOLServer that could allow remote users to gain access to protected information. The problem affects AOLServer on the Microsoft Windows 2000 platform.
AOLServer does not sufficiently handle access control requests. If a remote user knows the path directly to a password protected file hosted on the AOLServer, the user may access the file directly via the full path, circumventing authentication. This makes it possible for remote users to gain arbitrary access to sensitive files.
AOLServer is the open source, freely available HTTP server maintained in cooperation between AOL and the open source developer community. It offers features such as TCL interpretation, and dynamic content handling.
A problem has been discovered in AOLServer that could allow remote users to gain access to protected information. The problem affects AOLServer on the Microsoft Windows 2000 platform.
AOLServer does not sufficiently handle access control requests. If a remote user knows the path directly to a password protected file hosted on the AOLServer, the user may access the file directly via the full path, circumventing authentication. This makes it possible for remote users to gain arbitrary access to sensitive files.
Exploit / POC
AOLServer Password Protected File Arbitrary Read Access Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
AOLServer Password Protected File Arbitrary Read Access Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AOLServer Password Protected File Arbitrary Read Access Vulnerability
References:
References:
- AOLserver Homepage (AOL)