GeneWeb File Disclosure Vulnerability
BID:6549
Info
GeneWeb File Disclosure Vulnerability
| Bugtraq ID: | 6549 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1390 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2003 12:00AM |
| Updated: | Jul 11 2009 07:17PM |
| Credit: | This vulnerability was reported in the product changelog. |
| Vulnerable: |
GeneWeb GeneWeb 4.0 8 GeneWeb GeneWeb 4.0 7 GeneWeb GeneWeb 4.0 6 GeneWeb GeneWeb 4.0 5 |
| Not Vulnerable: |
GeneWeb GeneWeb 4.0 9 |
Discussion
GeneWeb File Disclosure Vulnerability
A file disclosure vulnerability has been reported for GeneWeb. Reportedly, GeneWeb does not adequately sanitize some input.
An attacker can exploit this vulnerability to craft a specially formed URL that can cause geneweb to disclose the contents of arbitrary files on the vulnerable system.
A file disclosure vulnerability has been reported for GeneWeb. Reportedly, GeneWeb does not adequately sanitize some input.
An attacker can exploit this vulnerability to craft a specially formed URL that can cause geneweb to disclose the contents of arbitrary files on the vulnerable system.
Exploit / POC
GeneWeb File Disclosure Vulnerability
There is no exploit code required.
There is no exploit code required.