BRS WebWeaver Web Server File Access Vulnerability
BID:6041
Info
BRS WebWeaver Web Server File Access Vulnerability
| Bugtraq ID: | 6041 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-1546 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 24 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Discovery of this vulnerability credited to Tamer Sahin <[email protected]>. |
| Vulnerable: |
BRS WebWeaver 1.0 1 |
| Not Vulnerable: | |
Discussion
BRS WebWeaver Web Server File Access Vulnerability
WebWeaver's Web server has a flaw that discloses the contents of potentially sensitive files to attackers.
It is possible for an attacker to bypass WebWeaver's input validation by constructing a request containing './' character sequences. Information obtained in this manner may allow an attacker to launch further, potentially destructive, attacks against the vulnerable server.
WebWeaver's Web server has a flaw that discloses the contents of potentially sensitive files to attackers.
It is possible for an attacker to bypass WebWeaver's input validation by constructing a request containing './' character sequences. Information obtained in this manner may allow an attacker to launch further, potentially destructive, attacks against the vulnerable server.
Exploit / POC
BRS WebWeaver Web Server File Access Vulnerability
This vulnerability can be exploited with a Web browser.
This vulnerability can be exploited with a Web browser.
Solution / Fix
BRS WebWeaver Web Server File Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
BRS WebWeaver Web Server File Access Vulnerability
References:
References: