Zeroo HTTP Server Directory Traversal Vulnerability
BID:6308
Info
Zeroo HTTP Server Directory Traversal Vulnerability
| Bugtraq ID: | 6308 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 22 2002 12:00AM |
| Updated: | Nov 22 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to "[email protected]" <[email protected]>. |
| Vulnerable: |
Zeroo HTTP Server 1.5 |
| Not Vulnerable: | |
Discussion
Zeroo HTTP Server Directory Traversal Vulnerability
It has been reported that Zeroo fails to properly sanitize web requests. By sending a malicious web request to the vulnerable server, using directory traversal sequences, it is possible for a remote attacker to access sensitive resources located outside of the web root.
An attacker is able to traverse outside of the established web root by using dot-dot-slash (../) directory traversal sequences. An attacker may be able to obtain any web server readable files from outside of the web root directory.
It has been reported that Zeroo fails to properly sanitize web requests. By sending a malicious web request to the vulnerable server, using directory traversal sequences, it is possible for a remote attacker to access sensitive resources located outside of the web root.
An attacker is able to traverse outside of the established web root by using dot-dot-slash (../) directory traversal sequences. An attacker may be able to obtain any web server readable files from outside of the web root directory.
Exploit / POC
Zeroo HTTP Server Directory Traversal Vulnerability
The following exploits were provided:
The following exploits were provided:
Solution / Fix
Zeroo HTTP Server Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Zeroo HTTP Server Directory Traversal Vulnerability
References:
References: