Apple QuickTime/Darwin Streaming Administration Server Parse_XML.CGI Directory Listing Vulnerability
BID:6955
Info
Apple QuickTime/Darwin Streaming Administration Server Parse_XML.CGI Directory Listing Vulnerability
| Bugtraq ID: | 6955 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0052 CVE-2003-0052 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2003 12:00AM |
| Updated: | Mar 19 2015 09:44AM |
| Credit: | The discovery of this vulnerability has been credited to Dave G. <[email protected]>. |
| Vulnerable: |
Apple Quicktime Streaming Server 4.1.1 Apple Darwin Streaming Server 4.1.2 |
| Not Vulnerable: | |
Discussion
Apple QuickTime/Darwin Streaming Administration Server Parse_XML.CGI Directory Listing Vulnerability
QuickTime/Darwin Streaming Administration Server is prone to an issue which may allow remote attackers to browse the contents of directories. This may lead to disclosure of sensitive information which may aid in further attacks against the system hosting the software. The attacker may need to view the source code of the page to view the directory listing output.
QuickTime/Darwin Streaming Administration Server is prone to an issue which may allow remote attackers to browse the contents of directories. This may lead to disclosure of sensitive information which may aid in further attacks against the system hosting the software. The attacker may need to view the source code of the page to view the directory listing output.
Exploit / POC
Apple QuickTime/Darwin Streaming Administration Server Parse_XML.CGI Directory Listing Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
Apple QuickTime/Darwin Streaming Administration Server Parse_XML.CGI Directory Listing Vulnerability
Solution:
Fixes are available:
Apple Darwin Streaming Server 4.1.2
Solution:
Fixes are available:
Apple Darwin Streaming Server 4.1.2
-
Apple MacOSXServerUpdate10.2.4.dmg
http://docs.info.apple.com/article.html?artnum=70171#English