PMSoftware Simple Web Server Directory Traversal Vulnerability
BID:57143
Info
PMSoftware Simple Web Server Directory Traversal Vulnerability
| Bugtraq ID: | 57143 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 02 2013 12:00AM |
| Updated: | Jan 02 2013 12:00AM |
| Credit: | CwG GeNiuS |
| Vulnerable: |
PMSoftware Simple Web Server 2.3-rc1 |
| Not Vulnerable: |
PMSoftware Simple Web Server 2.3-rc2 |
Discussion
PMSoftware Simple Web Server Directory Traversal Vulnerability
Simple Web Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary files within the context of the web server. Information harvested may aid in launching further attacks.
Simple Web Server versions prior to 2.3-rc1 are vulnerable; other versions may also be affected.
Simple Web Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary files within the context of the web server. Information harvested may aid in launching further attacks.
Simple Web Server versions prior to 2.3-rc1 are vulnerable; other versions may also be affected.
Solution / Fix
PMSoftware Simple Web Server Directory Traversal Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed it. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed it. Please contact the vendor for more information.