MultiHTML File Disclosure Vulnerability
BID:6711
Info
MultiHTML File Disclosure Vulnerability
| Bugtraq ID: | 6711 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2000 12:00AM |
| Updated: | Sep 13 2000 12:00AM |
| Credit: | Discovery of this issue is credited to Niels Heinen <[email protected]>. |
| Vulnerable: |
MultiHTML MultiHTML 1.5 |
| Not Vulnerable: |
MultiHTML MultiHTML 2.2 |
Discussion
MultiHTML File Disclosure Vulnerability
MultiHTML is prone to a file disclosure vulnerability.
It is possible for remote attackers to issue requests which are capable of disclosing sensitive webserver readable resources on the system hosting the software.
MultiHTML is prone to a file disclosure vulnerability.
It is possible for remote attackers to issue requests which are capable of disclosing sensitive webserver readable resources on the system hosting the software.
Exploit / POC
MultiHTML File Disclosure Vulnerability
This issue may be exploited with a web browser. The following example was submitted:
http://www.example.com/cgi-bin/multihtml.pl?multi=/etc/passwd%00html
This issue may be exploited with a web browser. The following example was submitted:
http://www.example.com/cgi-bin/multihtml.pl?multi=/etc/passwd%00html
Solution / Fix
MultiHTML File Disclosure Vulnerability
Solution:
It is not known when this issue was addressed by the vendor. Users are advised to upgrade to the recent version of the software, which is version 2.2 at the time of writing.
Solution:
It is not known when this issue was addressed by the vendor. Users are advised to upgrade to the recent version of the software, which is version 2.2 at the time of writing.