Sapio WebReflex Directory Traversal Vulnerability
BID:6327
Info
Sapio WebReflex Directory Traversal Vulnerability
| Bugtraq ID: | 6327 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2002 12:00AM |
| Updated: | Dec 06 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to "[email protected]" <[email protected]>. |
| Vulnerable: |
Sapio Design Ltd. WebReflex 1.53 |
| Not Vulnerable: | |
Discussion
Sapio WebReflex Directory Traversal Vulnerability
It has been reported that WebReflex fails to properly sanitize web requests. By sending a malicious web request to the vulnerable server, using directory traversal sequences, it is possible for a remote attacker to access sensitive resources located outside of the web root.
An attacker is able to traverse outside of the established web root by using dot-dot-slash (../) directory traversal sequences. An attacker may be able to obtain any web server readable files from outside of the web root directory.
It has been reported that WebReflex fails to properly sanitize web requests. By sending a malicious web request to the vulnerable server, using directory traversal sequences, it is possible for a remote attacker to access sensitive resources located outside of the web root.
An attacker is able to traverse outside of the established web root by using dot-dot-slash (../) directory traversal sequences. An attacker may be able to obtain any web server readable files from outside of the web root directory.
Exploit / POC
Sapio WebReflex Directory Traversal Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Sapio WebReflex Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Sapio WebReflex Directory Traversal Vulnerability
References:
References:
- WebReflex Home Page (Sapio Design Ltd.)
- =?iso-8859-1?Q?WebReflex_Directory_Traversal_Vulnerability?= ("[email protected]"
)