Summit Computer Networks Lil' HTTP Server Directory Disclosure Vulnerability
BID:4153
Info
Summit Computer Networks Lil' HTTP Server Directory Disclosure Vulnerability
| Bugtraq ID: | 4153 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2002 12:00AM |
| Updated: | Feb 21 2002 12:00AM |
| Credit: | Discovered by Tamer Sahin <[email protected]>. |
| Vulnerable: |
Summit Computer Networks Lil'HTTP 2.1 |
| Not Vulnerable: |
Summit Computer Networks Lil'HTTP 2.2 |
Discussion
Summit Computer Networks Lil' HTTP Server Directory Disclosure Vulnerability
Reportedly, it is possible for a remote user to reveal the contents of secure directories residing on a Lil' HTTP host.
Submitting a specially crafted request for a known secure directory, is reported to return the contents of the directory to the user.
Reportedly, it is possible for a remote user to reveal the contents of secure directories residing on a Lil' HTTP host.
Submitting a specially crafted request for a known secure directory, is reported to return the contents of the directory to the user.
Exploit / POC
Summit Computer Networks Lil' HTTP Server Directory Disclosure Vulnerability
No exploit code required.
No exploit code required.
Solution / Fix
Summit Computer Networks Lil' HTTP Server Directory Disclosure Vulnerability
Solution:
This issue has been addressed in version 2.2:
Summit Computer Networks Lil'HTTP 2.1
Solution:
This issue has been addressed in version 2.2:
Summit Computer Networks Lil'HTTP 2.1
-
Summit Computer Networks lilhtv22.zip
http://www.summitcn.com/lilhtv22.zip
References
Summit Computer Networks Lil' HTTP Server Directory Disclosure Vulnerability
References:
References:
- Lil' HTTP Homepage (Summit Computer Networks)