Falcon Web Server Directory Traversal Vulnerability
BID:743
Info
Falcon Web Server Directory Traversal Vulnerability
| Bugtraq ID: | 743 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 26 1999 12:00AM |
| Updated: | Oct 26 1999 12:00AM |
| Credit: | This bug was posted to the Bugtraq mailing list by Andrew Reiter of BindView <[email protected]> on Tue, 26 Oct 1999 . |
| Vulnerable: |
BlueFace Falcon Web Server 1.0 1006 |
| Not Vulnerable: |
BlueFace Falcon Web Server 1.0 1008 |
Discussion
Falcon Web Server Directory Traversal Vulnerability
The Falcon Webserver is a personal desktop webserver designed for low volume page serving. Certain versions of this software do not properly handle user supplied URL's. Therefore a user can browse outside of the web browser 'root' directory at any file on the file system depending on permissions.
A second problem exists wherein a longer than expected URL will elicit an error message from the server which betrays the location of the 'root' directory.
The Falcon Webserver is a personal desktop webserver designed for low volume page serving. Certain versions of this software do not properly handle user supplied URL's. Therefore a user can browse outside of the web browser 'root' directory at any file on the file system depending on permissions.
A second problem exists wherein a longer than expected URL will elicit an error message from the server which betrays the location of the 'root' directory.
Exploit / POC
Falcon Web Server Directory Traversal Vulnerability
Using the string '../' in a URL, an attacker can gain read access to any file outside of the intended web-published filesystem thta is readable by the webserver.
Using the string '../' in a URL, an attacker can gain read access to any file outside of the intended web-published filesystem thta is readable by the webserver.
Solution / Fix
Falcon Web Server Directory Traversal Vulnerability
Solution:
Blueface software has made the following patch available for this problem:
http://www.blueface.com/products.html#fws
Solution:
Blueface software has made the following patch available for this problem:
http://www.blueface.com/products.html#fws