WWWIsis File Disclosure Vulnerability
BID:4384
Info
WWWIsis File Disclosure Vulnerability
| Bugtraq ID: | 4384 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0508 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 28 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovery of this issue is credited to Klaus Ripke <[email protected]>. |
| Vulnerable: |
WWWIsis WWWIsis 3.45 WWWIsis WWWIsis 3.3 |
| Not Vulnerable: |
WWWIsis WWWIsis 5.0 WWWIsis WWWIsis 4.0 |
Discussion
WWWIsis File Disclosure Vulnerability
WWWIsis provides a web interface for accessing ISIS databases. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
A file disclosure vulnerability exists in WWWIsis. This may enable a remote attacker to disclose the contents of arbitrary web-readable files. This is due to insufficient validation of user-supplied input.
This issue has been reported for 3.x versions. Other versions are not affected by this vulnerability. Additionally, JavaISIS and other tools based on WWWIsis may also be affected.
WWWIsis provides a web interface for accessing ISIS databases. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
A file disclosure vulnerability exists in WWWIsis. This may enable a remote attacker to disclose the contents of arbitrary web-readable files. This is due to insufficient validation of user-supplied input.
This issue has been reported for 3.x versions. Other versions are not affected by this vulnerability. Additionally, JavaISIS and other tools based on WWWIsis may also be affected.
Exploit / POC
WWWIsis File Disclosure Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
WWWIsis File Disclosure Vulnerability
Solution:
This issue is not present in versions 4.0 and later. Those affected are advised to upgrade to the most recent version.
WWWIsis WWWIsis 3.3
WWWIsis WWWIsis 3.45
Solution:
This issue is not present in versions 4.0 and later. Those affected are advised to upgrade to the most recent version.
WWWIsis WWWIsis 3.3
-
WWWIsis WWWIsis 5.0
http://www.bireme.br/wwwisis/I/download.htm
WWWIsis WWWIsis 3.45
-
WWWIsis WWWIsis 5.0
http://www.bireme.br/wwwisis/I/download.htm