Thunderstone TEXIS Path Disclosure Vulnerability
BID:4035
Info
Thunderstone TEXIS Path Disclosure Vulnerability
| Bugtraq ID: | 4035 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0266 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2002 12:00AM |
| Updated: | Aug 27 2009 10:22PM |
| Credit: | Discovered by - phinegeek - <[email protected]>. |
| Vulnerable: |
Thunderstone Texis 3.0 |
| Not Vulnerable: |
Thunderstone Texis 4.3.1049406926 20030403 |
Discussion
Thunderstone TEXIS Path Disclosure Vulnerability
A vulnerability in TEXIS allows an attacker to view the full path to the web root.
If the attacker submits an HTTP request for an invalid path, the server will return an error page containing the path to the web root. System information may also be revealed.
Versions prior to TEXIS 4.03.1049406926 20030403 are vulnerable.
A vulnerability in TEXIS allows an attacker to view the full path to the web root.
If the attacker submits an HTTP request for an invalid path, the server will return an error page containing the path to the web root. System information may also be revealed.
Versions prior to TEXIS 4.03.1049406926 20030403 are vulnerable.
Exploit / POC
Thunderstone TEXIS Path Disclosure Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/texis/nonexistent/path/
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/texis/nonexistent/path/
Solution / Fix
Thunderstone TEXIS Path Disclosure Vulnerability
Solution:
Updates are available. Please contact the vendor for details.
Solution:
Updates are available. Please contact the vendor for details.
References
Thunderstone TEXIS Path Disclosure Vulnerability
References:
References:
- Texis Product Homepage (Thunderstone)
- texis(CGI) Path Disclosure Vulnerability ("- phinegeek -"
)