EServ Password-Protected File Access Vulnerability
BID:3838
Info
EServ Password-Protected File Access Vulnerability
| Bugtraq ID: | 3838 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0112 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 10 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | This vulnerability was submitted to BugTraq on January 10th, 2002 by "Tamer Sahin" <[email protected]>. |
| Vulnerable: |
Etype Eserv 2.97 Etype Eserv 2.96 Etype Eserv 2.95 BETA2 Etype Eserv 2.95 Etype Eserv 2.94 Etype Eserv 2.93 Etype Eserv 2.92 |
| Not Vulnerable: | |
Discussion
EServ Password-Protected File Access Vulnerability
EServ is a combination Mail, News, Web, FTP and Proxy Server for Microsoft Windows 9x/NT/2000 systems.
It is possible to construct a web request which is capable of accessing the contents of password protected files/folders on the webserver, such as the admin folder, which contains the administrative interface.
It should be noted that this vulnerability may only be exploited to access password-protected files in sub-folders of wwwroot.
EServ is a combination Mail, News, Web, FTP and Proxy Server for Microsoft Windows 9x/NT/2000 systems.
It is possible to construct a web request which is capable of accessing the contents of password protected files/folders on the webserver, such as the admin folder, which contains the administrative interface.
It should be noted that this vulnerability may only be exploited to access password-protected files in sub-folders of wwwroot.
Exploit / POC
EServ Password-Protected File Access Vulnerability
The following example will give the attacker access to the administrative interface:
http://host/./admin/
The following example will give the attacker access to the administrative interface:
http://host/./admin/
Solution / Fix
EServ Password-Protected File Access Vulnerability
Solution:
The vendor has released an update which addresses this issue.
Etype Eserv 2.92
Etype Eserv 2.93
Etype Eserv 2.94
Etype Eserv 2.95
Etype Eserv 2.95 BETA2
Etype Eserv 2.96
Etype Eserv 2.97
Solution:
The vendor has released an update which addresses this issue.
Etype Eserv 2.92
-
Etype Eserv3119.zip
ftp://ftp.eserv.ru/pub/beta/2.98/Eserv3119.zip
Etype Eserv 2.93
-
Etype Eserv3119.zip
ftp://ftp.eserv.ru/pub/beta/2.98/Eserv3119.zip
Etype Eserv 2.94
-
Etype Eserv3119.zip
ftp://ftp.eserv.ru/pub/beta/2.98/Eserv3119.zip
Etype Eserv 2.95
-
Etype Eserv3119.zip
ftp://ftp.eserv.ru/pub/beta/2.98/Eserv3119.zip
Etype Eserv 2.95 BETA2
-
Etype Eserv3119.zip
ftp://ftp.eserv.ru/pub/beta/2.98/Eserv3119.zip
Etype Eserv 2.96
-
Etype Eserv3119.zip
ftp://ftp.eserv.ru/pub/beta/2.98/Eserv3119.zip
Etype Eserv 2.97
-
Etype Eserv3119.zip
ftp://ftp.eserv.ru/pub/beta/2.98/Eserv3119.zip