Monkey HTTP Server File Disclosure Vulnerability
BID:5792
Info
Monkey HTTP Server File Disclosure Vulnerability
| Bugtraq ID: | 5792 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-2154 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2002 12:00AM |
| Updated: | Mar 19 2015 09:23AM |
| Credit: | Discovery credited to DownBload of Illegal Instruction Labs. |
| Vulnerable: |
Monkey Monkey HTTP Daemon 0.1.4 |
| Not Vulnerable: |
Monkey Monkey HTTP Daemon 0.5 Monkey Monkey HTTP Daemon 0.4.2 Monkey Monkey HTTP Daemon 0.4.1 Monkey Monkey HTTP Daemon 0.4 |
Discussion
Monkey HTTP Server File Disclosure Vulnerability
Monkey HTTP server is prone to a directory-traversal bug that may allow attackers to access sensitive files.
By passing a malicious query to a vulnerable server, an attacker can potentially gain access to arbitrary webserver-readable files. This issue occurs because the application fails to sufficiently validate the user-supplied input.
Monkey HTTP server is prone to a directory-traversal bug that may allow attackers to access sensitive files.
By passing a malicious query to a vulnerable server, an attacker can potentially gain access to arbitrary webserver-readable files. This issue occurs because the application fails to sufficiently validate the user-supplied input.
Exploit / POC
Monkey HTTP Server File Disclosure Vulnerability
An exploit is available:
An exploit is available:
Solution / Fix
Monkey HTTP Server File Disclosure Vulnerability
Solution:
The vendor addressed this vulnerability in December 2001.
Monkey Monkey HTTP Daemon 0.1.4
Solution:
The vendor addressed this vulnerability in December 2001.
Monkey Monkey HTTP Daemon 0.1.4
-
Monkey Monkey HTTP Daemon v0.5
http://monkeyd.sourceforge.net/down.php?vrs=MC41LjA=
References
Monkey HTTP Server File Disclosure Vulnerability
References:
References:
- Monkey HTTP Daemon Product Page (Monkey)