eshare Expressions Directory Traversal Vulnerability
BID:4029
Info
eshare Expressions Directory Traversal Vulnerability
| Bugtraq ID: | 4029 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0233 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | Discovered by Alex Forkosh <[email protected]>. |
| Vulnerable: |
eshare communications Inc eshare Expressions 2.0 eshare communications Inc eshare Expressions 1.0 |
| Not Vulnerable: | |
Discussion
eshare Expressions Directory Traversal Vulnerability
A directory traversal vulnerability has been discovered in the eshare Expressions, which may potentially disclose known files to remote attackers. This is due to insufficient validation of strings passed in web requests.
An attacker who submits a specially crafted web request containing double dot slash (../) character sequences may be able to browse known files residing on a vulnerable host.
A directory traversal vulnerability has been discovered in the eshare Expressions, which may potentially disclose known files to remote attackers. This is due to insufficient validation of strings passed in web requests.
An attacker who submits a specially crafted web request containing double dot slash (../) character sequences may be able to browse known files residing on a vulnerable host.
Exploit / POC
eshare Expressions Directory Traversal Vulnerability
No exploit code is required.
No exploit code is required.
Solution / Fix
eshare Expressions Directory Traversal Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
eshare Expressions Directory Traversal Vulnerability
References:
References:
- eshare Expressions Homepage (eshare communications Inc)