MondoSearch Source Disclosure Vulnerability
BID:5941
Info
MondoSearch Source Disclosure Vulnerability
| Bugtraq ID: | 5941 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1528 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Discovery credited to thefastkid. |
| Vulnerable: |
MondoSoft MondoSearch 4.4 |
| Not Vulnerable: | |
Discussion
MondoSearch Source Disclosure Vulnerability
A vulnerability has been discovered in MondoSearch v4.4.
Reportedly, by constructing a malicious http request, it is possible for an attacker to view the source code of arbitrary scripts located in the same directory or subdirectory as the vulnerable executable.
This issue could be exploited by an attacker to gain information needed to further exploit the target system.
Although this vulnerability was discovered in version 4.4 of the software, it is possible that earlier versions are also affected.
A vulnerability has been discovered in MondoSearch v4.4.
Reportedly, by constructing a malicious http request, it is possible for an attacker to view the source code of arbitrary scripts located in the same directory or subdirectory as the vulnerable executable.
This issue could be exploited by an attacker to gain information needed to further exploit the target system.
Although this vulnerability was discovered in version 4.4 of the software, it is possible that earlier versions are also affected.
Exploit / POC
MondoSearch Source Disclosure Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
MondoSearch Source Disclosure Vulnerability
Solution:
MondoSoft has made a security update available:
MondoSoft MondoSearch 4.4
Solution:
MondoSoft has made a security update available:
MondoSoft MondoSearch 4.4
-
MondoSoft ms44cd.zip
http://www.mondosoft.com/security-update.asp
References
MondoSearch Source Disclosure Vulnerability
References:
References: