FAQManager.CGI NULL Character Arbitrary File Disclosure Vulnerability
BID:3810
Info
FAQManager.CGI NULL Character Arbitrary File Disclosure Vulnerability
| Bugtraq ID: | 3810 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2002 12:00AM |
| Updated: | Jan 07 2002 12:00AM |
| Credit: | This vulnerability was submitted to BugTraq on January 7th, 2001 by Nu Omega Tau <[email protected]>. |
| Vulnerable: |
FAQManager FAQManager.cgi 2.2.5 FAQManager FAQManager.cgi 2.2.4 FAQManager FAQManager.cgi 2.2.3 FAQManager FAQManager.cgi 2.2.2 FAQManager FAQManager.cgi 2.2.1 FAQManager FAQManager.cgi 2.2 FAQManager FAQManager.cgi 2.1.2 FAQManager FAQManager.cgi 2.1.1 FAQManager FAQManager.cgi 2.1 FAQManager FAQManager.cgi 2.0 |
| Not Vulnerable: |
FAQManager FAQManager.cgi 2.2.6 |
Discussion
FAQManager.CGI NULL Character Arbitrary File Disclosure Vulnerability
FAQManager.cgi is a Perl script for maintaining a FAQ (Frequently Asked Questions) via a web interface. It will run on most Unix/Linux and Microsoft Windows platforms.
FAQManager does not properly filter certain types of input from incoming web requests. It is possible to append a NULL character (%00) to the of a web request and display the contents of an arbitrary web-readable file.
FAQManager.cgi is a Perl script for maintaining a FAQ (Frequently Asked Questions) via a web interface. It will run on most Unix/Linux and Microsoft Windows platforms.
FAQManager does not properly filter certain types of input from incoming web requests. It is possible to append a NULL character (%00) to the of a web request and display the contents of an arbitrary web-readable file.
Exploit / POC
FAQManager.CGI NULL Character Arbitrary File Disclosure Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
FAQManager.CGI NULL Character Arbitrary File Disclosure Vulnerability
Solution:
The vendor has addressed this issue in v2.2.6. However, it has been reported that the vendor's fix only partially addresses the issue at hand.
FAQManager FAQManager.cgi 2.0
FAQManager FAQManager.cgi 2.1
FAQManager FAQManager.cgi 2.1.1
FAQManager FAQManager.cgi 2.1.2
FAQManager FAQManager.cgi 2.2
FAQManager FAQManager.cgi 2.2.1
FAQManager FAQManager.cgi 2.2.2
FAQManager FAQManager.cgi 2.2.3
FAQManager FAQManager.cgi 2.2.4
FAQManager FAQManager.cgi 2.2.5
Solution:
The vendor has addressed this issue in v2.2.6. However, it has been reported that the vendor's fix only partially addresses the issue at hand.
FAQManager FAQManager.cgi 2.0
-
FAQManager FAQmanager_2.2.6.zip
http://www.fourteenminutes.com/code/faqmanager/FAQmanager_2.2.6.zip
FAQManager FAQManager.cgi 2.1
-
FAQManager FAQmanager_2.2.6.zip
http://www.fourteenminutes.com/code/faqmanager/FAQmanager_2.2.6.zip
FAQManager FAQManager.cgi 2.1.1
-
FAQManager FAQmanager_2.2.6.zip
http://www.fourteenminutes.com/code/faqmanager/FAQmanager_2.2.6.zip
FAQManager FAQManager.cgi 2.1.2
-
FAQManager FAQmanager_2.2.6.zip
http://www.fourteenminutes.com/code/faqmanager/FAQmanager_2.2.6.zip
FAQManager FAQManager.cgi 2.2
-
FAQManager FAQmanager_2.2.6.zip
http://www.fourteenminutes.com/code/faqmanager/FAQmanager_2.2.6.zip
FAQManager FAQManager.cgi 2.2.1
-
FAQManager FAQmanager_2.2.6.zip
http://www.fourteenminutes.com/code/faqmanager/FAQmanager_2.2.6.zip
FAQManager FAQManager.cgi 2.2.2
-
FAQManager FAQmanager_2.2.6.zip
http://www.fourteenminutes.com/code/faqmanager/FAQmanager_2.2.6.zip
FAQManager FAQManager.cgi 2.2.3
-
FAQManager FAQmanager_2.2.6.zip
http://www.fourteenminutes.com/code/faqmanager/FAQmanager_2.2.6.zip
FAQManager FAQManager.cgi 2.2.4
-
FAQManager FAQmanager_2.2.6.zip
http://www.fourteenminutes.com/code/faqmanager/FAQmanager_2.2.6.zip
FAQManager FAQManager.cgi 2.2.5
-
FAQManager FAQmanager_2.2.6.zip
http://www.fourteenminutes.com/code/faqmanager/FAQmanager_2.2.6.zip
References
FAQManager.CGI NULL Character Arbitrary File Disclosure Vulnerability
References:
References:
- FAQManager Homepage (FAQManager)