Seanox DevWex File Disclosure Vulnerability
BID:4978
Info
Seanox DevWex File Disclosure Vulnerability
| Bugtraq ID: | 4978 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 08 2002 12:00AM |
| Updated: | Jun 08 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Kistler Ueli <[email protected]>. |
| Vulnerable: |
Seanox DevWex Windows Binary 1.2002.520 |
| Not Vulnerable: |
Seanox DevWex Windows Binary 1.2002.601 |
Discussion
Seanox DevWex File Disclosure Vulnerability
The Seanox DevWex Windows binary version is prone to an issue which may cause arbitrary web-readable files to be disclosed to remote attackers. This problem occurs because DevWex does not sufficiently filter '..\' sequences from web requests.
The Seanox DevWex Windows binary version is prone to an issue which may cause arbitrary web-readable files to be disclosed to remote attackers. This problem occurs because DevWex does not sufficiently filter '..\' sequences from web requests.
Exploit / POC
Seanox DevWex File Disclosure Vulnerability
This issue may be exploited with a web browser. The following example was submitted:
GET /..\..\..\..\anyfile
This issue may be exploited with a web browser. The following example was submitted:
GET /..\..\..\..\anyfile