Xataface '-lang' Parameter Directory Traversal Vulnerability
BID:49044
Info
Xataface '-lang' Parameter Directory Traversal Vulnerability
| Bugtraq ID: | 49044 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 2011 12:00AM |
| Updated: | Aug 05 2011 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Xataface Xataface 1.3rc4 Xataface Xataface 1.3rc3 Xataface Xataface 1.3rc2 Xataface Xataface 1.3rc1 Xataface Xataface 1.2.6 Xataface Xataface 1.2.5 Xataface Xataface 1.2 Xataface Xataface 1.1 Xataface Xataface 1.0 |
| Not Vulnerable: |
Xataface Xataface 1.3RC5 Xataface Xataface 1.2.7 Xataface Xataface 1.1.6 |
Discussion
Xataface '-lang' Parameter Directory Traversal Vulnerability
Xataface is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to obtain arbitrary local files in the context of the Web server process.
Xataface versions prior to 1.1.6, 1.2.7, and 1.3rc5 are vulnerable.
Xataface is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to obtain arbitrary local files in the context of the Web server process.
Xataface versions prior to 1.1.6, 1.2.7, and 1.3rc5 are vulnerable.
Exploit / POC
Xataface '-lang' Parameter Directory Traversal Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Xataface '-lang' Parameter Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Xataface '-lang' Parameter Directory Traversal Vulnerability
References:
References:
- Xataface Security Release 1.3rc5 (Critical Bugfix) (Xataface)
- Xataface Homepage (Xataface)