Mongoose Space String Remote File Disclosure Vulnerability
BID:38145
Info
Mongoose Space String Remote File Disclosure Vulnerability
| Bugtraq ID: | 38145 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2010 12:00AM |
| Updated: | Feb 08 2010 12:00AM |
| Credit: | Pouya Daneshmand |
| Vulnerable: |
Mongoose Mongoose 2.8 |
| Not Vulnerable: | |
Discussion
Mongoose Space String Remote File Disclosure Vulnerability
Mongoose is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view the source code of files in the context of the server process, which may aid in further attacks.
This issue affects Mongoose 2.8; other versions may be vulnerable as well.
Mongoose is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view the source code of files in the context of the server process, which may aid in further attacks.
This issue affects Mongoose 2.8; other versions may be vulnerable as well.
Exploit / POC
Mongoose Space String Remote File Disclosure Vulnerability
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/file.php%20%20%20
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/file.php%20%20%20
Solution / Fix
Mongoose Space String Remote File Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Mongoose Space String Remote File Disclosure Vulnerability
References:
References: