Mongoose Slash Character Remote File Disclosure Vulnerability
BID:42051
Info
Mongoose Slash Character Remote File Disclosure Vulnerability
| Bugtraq ID: | 42051 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4535 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 28 2010 12:00AM |
| Updated: | Jul 28 2010 12:00AM |
| Credit: | Dr_IDE |
| Vulnerable: |
Mongoose Mongoose 2.8 |
| Not Vulnerable: | |
Discussion
Mongoose Slash Character Remote File Disclosure Vulnerability
Mongoose is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view the source code of files in the context of the server process, which may aid in further attacks.
This issue affects Mongoose 2.8; other versions may be vulnerable as well.
Mongoose is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view the source code of files in the context of the server process, which may aid in further attacks.
This issue affects Mongoose 2.8; other versions may be vulnerable as well.
Exploit / POC
Mongoose Slash Character Remote File Disclosure Vulnerability
Attackers can exploit this issue via a browser.
The following example URIs are available:
http://www.example.com/index.html/
http://www.example.com/index.php/
Attackers can exploit this issue via a browser.
The following example URIs are available:
http://www.example.com/index.html/
http://www.example.com/index.php/
References
Mongoose Slash Character Remote File Disclosure Vulnerability
References:
References:
- Mongoose Project Page (Mongoose)