Perl-HTTPd File Disclosure Vulnerability
BID:6497
Info
Perl-HTTPd File Disclosure Vulnerability
| Bugtraq ID: | 6497 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 31 2002 12:00AM |
| Updated: | Dec 31 2002 12:00AM |
| Credit: | This vulnerability was reported in the product changelog. |
| Vulnerable: |
Perl-HTTPd Perl-HTTPd 1.0.1 Perl-HTTPd Perl-HTTPd 1.0 |
| Not Vulnerable: |
Perl-HTTPd Perl-HTTPd 1.0.2 |
Discussion
Perl-HTTPd File Disclosure Vulnerability
It has been reported that Perl-HTTPd fails to properly sanitize some web requests. By exploiting this issue, an attacker is able to traverse outside of the established web root by using dot-dot-slash (../) directory traversal sequences. An attacker may be able to obtain any web server readable files from outside of the web root directory.
It has been reported that Perl-HTTPd fails to properly sanitize some web requests. By exploiting this issue, an attacker is able to traverse outside of the established web root by using dot-dot-slash (../) directory traversal sequences. An attacker may be able to obtain any web server readable files from outside of the web root directory.