BPM Studio Pro HTTPD Directory Traversal Vulnerability
BID:4198
Info
BPM Studio Pro HTTPD Directory Traversal Vulnerability
| Bugtraq ID: | 4198 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0331 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | This vulnerability was reported to BugTraq by "\]\[-\]\[UNTER" <[email protected]>. |
| Vulnerable: |
BPM Studio Pro BPM Studio Pro 4.2 |
| Not Vulnerable: | |
Discussion
BPM Studio Pro HTTPD Directory Traversal Vulnerability
BPM Studio Pro is a shareware MP3 mixer and player. It runs on Microsoft Windows operating systems. BPM Studio Pro includes a HTTP server for managing the player via a web interface.
The BPM Studio Pro HTTPD does not adequately filter dot-dot-slash (../) sequences from web requests. As a result, it is possible for a remote attacker to break out of wwwroot and browse the filesystem of the host. This may lead to disclosure of sensitive information as the remote attacker may display arbitrary web-readable files.
This is compounded by the fact that webservers on Microsoft Windows systems are normally run with SYSTEM privileges.
This issue reportedly affects BPM Studio Pro 4.2. Earlier versions may also be affected. It also should be noted that the HTTPD implementation is not enabled by default.
BPM Studio Pro is a shareware MP3 mixer and player. It runs on Microsoft Windows operating systems. BPM Studio Pro includes a HTTP server for managing the player via a web interface.
The BPM Studio Pro HTTPD does not adequately filter dot-dot-slash (../) sequences from web requests. As a result, it is possible for a remote attacker to break out of wwwroot and browse the filesystem of the host. This may lead to disclosure of sensitive information as the remote attacker may display arbitrary web-readable files.
This is compounded by the fact that webservers on Microsoft Windows systems are normally run with SYSTEM privileges.
This issue reportedly affects BPM Studio Pro 4.2. Earlier versions may also be affected. It also should be noted that the HTTPD implementation is not enabled by default.
Exploit / POC
BPM Studio Pro HTTPD Directory Traversal Vulnerability
The following example was submitted:
http://BPM-HOST/../../../../autoexec.bat
The following example was submitted:
http://BPM-HOST/../../../../autoexec.bat
Solution / Fix
BPM Studio Pro HTTPD Directory Traversal Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.