Sun Cobalt RaQ Directory Traversal File Reading Vulnerability
BID:4208
Info
Sun Cobalt RaQ Directory Traversal File Reading Vulnerability
| Bugtraq ID: | 4208 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0347 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | This vulnerability discovery credited to Alex Hernandez <[email protected]>. |
| Vulnerable: |
Cobalt RaQ 4.0 Cobalt RaQ 3.0 Cobalt RaQ 2.0 |
| Not Vulnerable: | |
Discussion
Sun Cobalt RaQ Directory Traversal File Reading Vulnerability
RaQ is a server appliance originally developed by Cobalt. It is now distributed and maintained by Sun Microsystems.
It has been reported that Cobalt RaQ appliances are vulnerable to a directory traversal attack. Using this attack, it is possible for a remote user to read sensitive configuration files, such as .htaccess files, and could potentially result in unauthorized access to restricted information. It is unknown whether this attack will permit escape of the HTTP root directory.
RaQ is a server appliance originally developed by Cobalt. It is now distributed and maintained by Sun Microsystems.
It has been reported that Cobalt RaQ appliances are vulnerable to a directory traversal attack. Using this attack, it is possible for a remote user to read sensitive configuration files, such as .htaccess files, and could potentially result in unauthorized access to restricted information. It is unknown whether this attack will permit escape of the HTTP root directory.
Exploit / POC
Sun Cobalt RaQ Directory Traversal File Reading Vulnerability
This vulnerability may be exploit with a web browser.
This vulnerability may be exploit with a web browser.
Solution / Fix
Sun Cobalt RaQ Directory Traversal File Reading Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Sun Cobalt RaQ Directory Traversal File Reading Vulnerability
References:
References: