Avenger's News System Directory Traversal Vulnerability
BID:4147
Info
Avenger's News System Directory Traversal Vulnerability
| Bugtraq ID: | 4147 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0307 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | This issue was submitted to BugTraq on February 21st, 2002 by "b0iler _" <[email protected]>. |
| Vulnerable: |
Avenger's News System Avenger's News System 2.1 1 Avenger's News System Avenger's News System 2.0 1 |
| Not Vulnerable: | |
Discussion
Avenger's News System Directory Traversal Vulnerability
Avenger's News System (ANS) is a simple form-based web site management tool written in Perl. It will run on most Unix and Linux variants.
ANS does not filter dot-dot-slash (../) sequences from web requests, making it prone to directory traversal attacks. As a result, the attacker may display the contents of arbitrary web-readable files.
Information disclosed in this manner may aid the attacker in further "intelligent" attacks against the host.
Avenger's News System (ANS) is a simple form-based web site management tool written in Perl. It will run on most Unix and Linux variants.
ANS does not filter dot-dot-slash (../) sequences from web requests, making it prone to directory traversal attacks. As a result, the attacker may display the contents of arbitrary web-readable files.
Information disclosed in this manner may aid the attacker in further "intelligent" attacks against the host.
Exploit / POC
Avenger's News System Directory Traversal Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
References
Avenger's News System Directory Traversal Vulnerability
References:
References:
- Avenger's News System Homepage (Avenger's News System)