MochiWeb CVE-2012-5641 Directory Traversal Vulnerability
BID:57313
Info
MochiWeb CVE-2012-5641 Directory Traversal Vulnerability
| Bugtraq ID: | 57313 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-5641 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 14 2013 12:00AM |
| Updated: | Jan 14 2013 12:00AM |
| Credit: | Sriram Melkote |
| Vulnerable: |
Mochiweb Project Mochiweb 0 Apache CouchDB 1.2 Apache CouchDB 1.1.1 Apache CouchDB 1.0.3 Apache CouchDB 1.0.2 Apache CouchDB 1.0.1 |
| Not Vulnerable: |
Apache CouchDB 1.2.1 Apache CouchDB 1.1.2 Apache CouchDB 1.0.4 |
Discussion
MochiWeb CVE-2012-5641 Directory Traversal Vulnerability
MochiWeb is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
MochiWeb is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Exploit / POC
MochiWeb CVE-2012-5641 Directory Traversal Vulnerability
An attacker can exploit the issue through a browser.
An attacker can exploit the issue through a browser.
Solution / Fix
MochiWeb CVE-2012-5641 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
MochiWeb CVE-2012-5641 Directory Traversal Vulnerability
References:
References:
- Apache CouchDB Homepage (Apache Software Foundation)
- CVE-2012-5641 Apache CouchDB Information disclosure via unescaped backslashes in (Full Disclosure)
- Issue 92: Do not allow backslashes in path (security) (melkote)
- MochiWeb HomePage (GitGub)