JWalk Application Server File Disclosure Vulnerability
BID:7160
Info
JWalk Application Server File Disclosure Vulnerability
| Bugtraq ID: | 7160 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2003 12:00AM |
| Updated: | Mar 20 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Andy Davis. |
| Vulnerable: |
Seagull Software J walk 3.2 c9 |
| Not Vulnerable: |
Seagull Software J walk 3.3 c4 |
Discussion
JWalk Application Server File Disclosure Vulnerability
It has been reported that JWalk Server fails to properly sanitize web requests.
By sending a malicious web request to the vulnerable server, using encoded directory traversal sequences, it is possible for a remote attacker to access sensitive resources located outside of the web root.
Disclosure of sensitive system files may aid the attacker in launching further attacks against the target system.
It has been reported that JWalk Server fails to properly sanitize web requests.
By sending a malicious web request to the vulnerable server, using encoded directory traversal sequences, it is possible for a remote attacker to access sensitive resources located outside of the web root.
Disclosure of sensitive system files may aid the attacker in launching further attacks against the target system.
Solution / Fix
JWalk Application Server File Disclosure Vulnerability
Solution:
JWalk 3.3c4 has been reported to be unaffected by this vulnerability. Users are advised to contact the vendor for further information.
Solution:
JWalk 3.3c4 has been reported to be unaffected by this vulnerability. Users are advised to contact the vendor for further information.
References
JWalk Application Server File Disclosure Vulnerability
References:
References:
- J Walk Homepage (Seagull Software)