RadioBird Software WebServer 4 All Directory Traversal Vulnerability
BID:5968
Info
RadioBird Software WebServer 4 All Directory Traversal Vulnerability
| Bugtraq ID: | 5968 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1213 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 15 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Discovery of this vulnerability credited to Tamer Sahin ([email protected]). |
| Vulnerable: |
RadioBird Software WebServer 4 All 1.27 RadioBird Software WebServer 4 All 1.23 |
| Not Vulnerable: |
RadioBird Software WebServer 4 All 1.30 |
Discussion
RadioBird Software WebServer 4 All Directory Traversal Vulnerability
A vulnerability has been discovered in WebServer 4 All.
It has been reported that WebServer 4 All does not properly sanitize web requests. By sending a malicious web request to the vulnerable server, using URL encoded characters, it is possible for a remote attacker to access sensitive resources located outside of the web root.
Disclosure of sensitive system files may aid the attacker in launching further attacks against the target system.
A vulnerability has been discovered in WebServer 4 All.
It has been reported that WebServer 4 All does not properly sanitize web requests. By sending a malicious web request to the vulnerable server, using URL encoded characters, it is possible for a remote attacker to access sensitive resources located outside of the web root.
Disclosure of sensitive system files may aid the attacker in launching further attacks against the target system.
Exploit / POC
RadioBird Software WebServer 4 All Directory Traversal Vulnerability
This issue can be exploited with a web browser.
This issue can be exploited with a web browser.
Solution / Fix
RadioBird Software WebServer 4 All Directory Traversal Vulnerability
Solution:
The vendor has stated that WebServer 4 All 1.30 is not vulnerable to this issue. Users are advised to upgrade to the newest version of WebServer 4 All:
RadioBird Software WebServer 4 All 1.23
RadioBird Software WebServer 4 All 1.27
Solution:
The vendor has stated that WebServer 4 All 1.30 is not vulnerable to this issue. Users are advised to upgrade to the newest version of WebServer 4 All:
RadioBird Software WebServer 4 All 1.23
-
RadioBird Software w4asetup.exe
ftp://ftp.freeware.lt/anonymous/Soft/w4asetup.exe
RadioBird Software WebServer 4 All 1.27
-
RadioBird Software w4asetup.exe
ftp://ftp.freeware.lt/anonymous/Soft/w4asetup.exe