Kebi Academy 2001 Input Validation Vulnerability
BID:7125
Info
Kebi Academy 2001 Input Validation Vulnerability
| Bugtraq ID: | 7125 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2003 12:00AM |
| Updated: | Mar 17 2003 12:00AM |
| Credit: | Discovery of this issue is credited to "dong-h0un U" <[email protected]>. |
| Vulnerable: |
Nara Vision Kebi Academy 2001 |
| Not Vulnerable: | |
Discussion
Kebi Academy 2001 Input Validation Vulnerability
Kebi Academy 2001 does not sufficiently validate input supplied via URI parameters. As a result it has been reported that it is possible to retrieve arbitrary files which are readable by the web server. It has also been reported that it is possible to upload malicious files to the server. This could result in disclosure of sensitive information or execution of arbitrary commands in the context of the web server.
Kebi Academy 2001 does not sufficiently validate input supplied via URI parameters. As a result it has been reported that it is possible to retrieve arbitrary files which are readable by the web server. It has also been reported that it is possible to upload malicious files to the server. This could result in disclosure of sensitive information or execution of arbitrary commands in the context of the web server.
Exploit / POC
Kebi Academy 2001 Input Validation Vulnerability
This issue can be exploited with a web browser. The following example was submitted:
http://www.example.com/k/home?dir=/&file=../../../../../../../../etc/passwd&lang=kor
This issue can be exploited with a web browser. The following example was submitted:
http://www.example.com/k/home?dir=/&file=../../../../../../../../etc/passwd&lang=kor
Solution / Fix
Kebi Academy 2001 Input Validation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Kebi Academy 2001 Input Validation Vulnerability
References:
References:
- Nara Vision Homepage (Nara Vision)
- [INetCop Security Advisory #2002-0x82-013] Kebi Academy 2001 Web Solution ("dong-h0un U"
)