Web File Browser 'webFileBrowser.php' Arbitrary File Download Vulnerability
BID:50508
Info
Web File Browser 'webFileBrowser.php' Arbitrary File Download Vulnerability
| Bugtraq ID: | 50508 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-4831 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2011 12:00AM |
| Updated: | Dec 16 2011 06:08PM |
| Credit: | Sangyun YOO |
| Vulnerable: |
cgdave Web File Browser 0.4b14 |
| Not Vulnerable: | |
Discussion
Web File Browser 'webFileBrowser.php' Arbitrary File Download Vulnerability
Web File Browser is prone to a vulnerability that lets attackers download arbitrary files. This issue occurs because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to download arbitrary files within the context of the application. Information harvested may aid in launching further attacks.
Web File Browser 0.4b14 is affected; other versions may also be vulnerable.
Web File Browser is prone to a vulnerability that lets attackers download arbitrary files. This issue occurs because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to download arbitrary files within the context of the application. Information harvested may aid in launching further attacks.
Web File Browser 0.4b14 is affected; other versions may also be vulnerable.
Exploit / POC
Web File Browser 'webFileBrowser.php' Arbitrary File Download Vulnerability
An attacker can exploit this issue using a browser.
The following example URI is available:
http://www.example.com/webFileBrowser.php?act=download&subdir=&sortby=name&file=..%2f..%2f..%2f..%2f..%2f[localfile]
An attacker can exploit this issue using a browser.
The following example URI is available:
http://www.example.com/webFileBrowser.php?act=download&subdir=&sortby=name&file=..%2f..%2f..%2f..%2f..%2f[localfile]
Solution / Fix
Web File Browser 'webFileBrowser.php' Arbitrary File Download Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Web File Browser 'webFileBrowser.php' Arbitrary File Download Vulnerability
References:
References:
- Web File Browser Home page (cgdave)