Sambar Server File Disclosure Vulnerability
BID:7208
Info
Sambar Server File Disclosure Vulnerability
| Bugtraq ID: | 7208 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 27 2003 12:00AM |
| Updated: | Mar 27 2003 12:00AM |
| Credit: | Discovery is credited to Gregory Le Bras <[email protected]>. |
| Vulnerable: |
Sambar Server 5.3 b4 Sambar Server 5.2 b Sambar Server 5.2 Sambar Server 5.1 |
| Not Vulnerable: | |
Discussion
Sambar Server File Disclosure Vulnerability
Sambar Server does not properly validate URL requests to iecreate.stm and ieedit.stm. By appending directory traversal sequences such as '../' to requests for these applications, it is possible for a remote user to reveal the contents of directories on the webserver.
Sambar Server does not properly validate URL requests to iecreate.stm and ieedit.stm. By appending directory traversal sequences such as '../' to requests for these applications, it is possible for a remote user to reveal the contents of directories on the webserver.
Exploit / POC
Sambar Server File Disclosure Vulnerability
This vulnerability may be exploited with a web browser.
This vulnerability may be exploited with a web browser.
Solution / Fix
Sambar Server File Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.