Apache 2 WebDAV CGI POST Request Information Disclosure Vulnerability
BID:6065
Info
Apache 2 WebDAV CGI POST Request Information Disclosure Vulnerability
| Bugtraq ID: | 6065 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-1156 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 29 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Vulnerability first detailed in the product changelog. |
| Vulnerable: |
HP VirtualVault 4.6 HP VirtualVault 4.5 HP OpenView Network Node Manager 6.2 Solaris HP OpenView Network Node Manager 6.2 HP-UX 11.X HP OpenView Network Node Manager 6.2 HP-UX 10.X HP HP-UX 11.22 HP HP-UX 11.20 HP HP-UX 11.11 HP HP-UX 11.0 Apache Apache 2.0.42 Apache Apache 2.0.41 Apache Apache 2.0.40 Apache Apache 2.0.39 Apache Apache 2.0.38 Apache Apache 2.0.37 Apache Apache 2.0.36 Apache Apache 2.0.35 Apache Apache 2.0 |
| Not Vulnerable: |
HP OpenView Network Node Manager 5.0.2 Windows NT 3.51/4.0 HP OpenView Network Node Manager 5.0 1 Solaris HP OpenView Network Node Manager 5.0 1 HP-UX HP OpenView Network Node Manager 5.0 1 Apache Apache 2.0.43 |
Discussion
Apache 2 WebDAV CGI POST Request Information Disclosure Vulnerability
An information disclosure vulnerability has been for Apache. The vulnerability occurs due to inadequate checks being performed on CGI scripts. This vulnerability exists only when both WebDAV and CGI are enabled for folders.
An attacker can exploit this vulnerability by making a POST request to a CGI script. Due to improper interaction between WebDAV and CGI scripts, this will result in the Web server returning the contents of the CGI script to the remote attacker.
An information disclosure vulnerability has been for Apache. The vulnerability occurs due to inadequate checks being performed on CGI scripts. This vulnerability exists only when both WebDAV and CGI are enabled for folders.
An attacker can exploit this vulnerability by making a POST request to a CGI script. Due to improper interaction between WebDAV and CGI scripts, this will result in the Web server returning the contents of the CGI script to the remote attacker.
Exploit / POC
Apache 2 WebDAV CGI POST Request Information Disclosure Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Apache 2 WebDAV CGI POST Request Information Disclosure Vulnerability
Solution:
Apache 2.0.43 is not vulnerable to this issue:
HP has released a security bulletin. Customers of HP-UX are advised to download Apache 2.0.43.00 product bundles from:
http://www.software.hp.com/ISS_products_list.html
HP has advised NNM (Network Node Manager) customers to refrain from installing these product bundles. Further details are available in the referenced advisory.
Fixes available:
HP HP-UX 11.0
HP HP-UX 11.11
HP HP-UX 11.20
HP HP-UX 11.22
Apache Apache 2.0
Apache Apache 2.0.35
Apache Apache 2.0.36
Apache Apache 2.0.37
Apache Apache 2.0.38
Apache Apache 2.0.39
Apache Apache 2.0.40
Apache Apache 2.0.41
Apache Apache 2.0.42
HP VirtualVault 4.5
HP VirtualVault 4.6
HP OpenView Network Node Manager 6.2 Solaris
HP OpenView Network Node Manager 6.2 HP-UX 11.X
HP OpenView Network Node Manager 6.2 HP-UX 10.X
Solution:
Apache 2.0.43 is not vulnerable to this issue:
HP has released a security bulletin. Customers of HP-UX are advised to download Apache 2.0.43.00 product bundles from:
http://www.software.hp.com/ISS_products_list.html
HP has advised NNM (Network Node Manager) customers to refrain from installing these product bundles. Further details are available in the referenced advisory.
Fixes available:
HP HP-UX 11.0
-
HP Apache 2.0.43.00
http://www.software.hp.com/ISS_products_list.html
HP HP-UX 11.11
-
HP Apache 2.0.43.00
http://www.software.hp.com/ISS_products_list.html
HP HP-UX 11.20
-
HP Apache 2.0.43.00
http://www.software.hp.com/ISS_products_list.html
HP HP-UX 11.22
-
HP Apache 2.0.43.00
http://www.software.hp.com/ISS_products_list.html
Apache Apache 2.0
-
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/
Apache Apache 2.0.35
-
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/
Apache Apache 2.0.36
-
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/
Apache Apache 2.0.37
-
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/
Apache Apache 2.0.38
-
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/
Apache Apache 2.0.39
-
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/
Apache Apache 2.0.40
-
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/
Apache Apache 2.0.41
-
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/
Apache Apache 2.0.42
-
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/
HP VirtualVault 4.5
-
HP PHSS_28098
s700_800 11.04 Virtualvault 4.5 OWS update
http://itrc.hp.com/ -
HP PHSS_28111
s700_800 11.04 Virtualvault 4.5 IWS Update
http://itrc.hp.com/
HP VirtualVault 4.6
-
HP PHSS_28090
s700_800 11.04 Virtualvault 4.6 IWS update
http://itrc.hp.com/ -
HP PHSS_28099
s700_800 11.04 Virtualvault 4.6 OWS update
http://itrc.hp.com/
HP OpenView Network Node Manager 6.2 Solaris
-
HP PSOV_03251
http://ovweb.external.hp.com/cpe/patches/
HP OpenView Network Node Manager 6.2 HP-UX 11.X
-
HP PHSS_28705
http://ovweb.external.hp.com/cpe/patches/
HP OpenView Network Node Manager 6.2 HP-UX 10.X
-
HP PHSS_28704
http://ovweb.external.hp.com/cpe/patches/
References
Apache 2 WebDAV CGI POST Request Information Disclosure Vulnerability
References:
References:
- Apache httpd Release 2.0 Changes (Apache Software Foundation)
- Vulnerability Note VU#910713 (CERT)