myServer File Disclosure Vulnerability
BID:6359
Info
myServer File Disclosure Vulnerability
| Bugtraq ID: | 6359 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2002 12:00AM |
| Updated: | Dec 11 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to "dong-h0un U" <[email protected]>. |
| Vulnerable: |
myServer myServer 0.11 myServer myServer 0.2 |
| Not Vulnerable: | |
Discussion
myServer File Disclosure Vulnerability
It has been reported that myServer fails to properly sanitize web requests. By sending a malicious web request to the vulnerable server, using directory traversal sequences, it is possible for a remote attacker to access sensitive resources located outside of the web root.
It has been reported that myServer fails to properly sanitize web requests. By sending a malicious web request to the vulnerable server, using directory traversal sequences, it is possible for a remote attacker to access sensitive resources located outside of the web root.
Exploit / POC
myServer File Disclosure Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
myServer File Disclosure Vulnerability
Solution:
The vendor has reported that this vulnerability has been addressed in the latest version of the product. Users are strongly advised to upgrade.
myServer myServer 0.11
myServer myServer 0.2
Solution:
The vendor has reported that this vulnerability has been addressed in the latest version of the product. Users are strongly advised to upgrade.
myServer myServer 0.11
-
myServer myServerSRC-0.4.zip
http://sourceforge.net/project/showfiles.php?group_id=63119
myServer myServer 0.2
-
myServer myServerSRC-0.4.zip
http://sourceforge.net/project/showfiles.php?group_id=63119
References
myServer File Disclosure Vulnerability
References:
References:
- myServer Home Page (myServer)
- Directory traversing bug in 'myServer' webserver. ("dong-h0un U"
)