AjaXplorer 'doc_file' Parameter Local File Disclosure Vulnerability
BID:51960
Info
AjaXplorer 'doc_file' Parameter Local File Disclosure Vulnerability
| Bugtraq ID: | 51960 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 10 2012 12:00AM |
| Updated: | Feb 10 2012 12:00AM |
| Credit: | Han Lee |
| Vulnerable: |
AjaXplorer AjaXplorer 4.0.1 |
| Not Vulnerable: |
AjaXplorer AjaXplorer 4.0.2 |
Discussion
AjaXplorer 'doc_file' Parameter Local File Disclosure Vulnerability
AjaXplorer is prone to a local file-disclosure vulnerability because it fails to adequately validate user-supplied input.
Exploiting this vulnerability would allow an attacker to obtain potentially sensitive information from local text files on computers running the vulnerable application. This may aid in further attacks.
AjaXplorer 4.0.1 is vulnerable; other versions are also affected.
AjaXplorer is prone to a local file-disclosure vulnerability because it fails to adequately validate user-supplied input.
Exploiting this vulnerability would allow an attacker to obtain potentially sensitive information from local text files on computers running the vulnerable application. This may aid in further attacks.
AjaXplorer 4.0.1 is vulnerable; other versions are also affected.
Exploit / POC
AjaXplorer 'doc_file' Parameter Local File Disclosure Vulnerability
An attacker can exploit these issues through a browser.
An attacker can exploit these issues through a browser.
Solution / Fix
AjaXplorer 'doc_file' Parameter Local File Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
AjaXplorer 'doc_file' Parameter Local File Disclosure Vulnerability
References:
References:
- AjaXplorer 4.0.2 (AjaXplorer)
- AjaXplorer Homepage (AjaXplorer)