Boa Webserver File Disclosure Vulnerability
BID:7544
Info
Boa Webserver File Disclosure Vulnerability
| Bugtraq ID: | 7544 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2003 12:00AM |
| Updated: | May 09 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "morning_wood" <[email protected]> |
| Vulnerable: |
Boa Webserver 0.92 r |
| Not Vulnerable: | |
Discussion
Boa Webserver File Disclosure Vulnerability
Boa Webserver has been reported prone to a file disclosure vulnerability. The issue presents itself due to a lack of sufficient sanitization performed on user supplied HTTP requests.
Reportedly an attacker may exploit this vulnerability to disclose any webserver readable file on the vulnerable system.
This issue may be related to the vulnerability reported in BID 1770.
It is noted that this issue only affects PowerLinkT WAN Aggregator running firmware 1.7.3.1.
Boa Webserver has been reported prone to a file disclosure vulnerability. The issue presents itself due to a lack of sufficient sanitization performed on user supplied HTTP requests.
Reportedly an attacker may exploit this vulnerability to disclose any webserver readable file on the vulnerable system.
This issue may be related to the vulnerability reported in BID 1770.
It is noted that this issue only affects PowerLinkT WAN Aggregator running firmware 1.7.3.1.
Exploit / POC
Boa Webserver File Disclosure Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Boa Webserver File Disclosure Vulnerability
Solution:
This issue has reportedly been resolved in the current version of this software.
It is noted that this issue only affects PowerLinkT WAN Aggregator running firmware 1.7.3.1. Newer revisions are not affected. Users should contact the vendor for information about obtaining upgrades if they are affected by the vulnerability.
Boa Webserver 0.92 r
Solution:
This issue has reportedly been resolved in the current version of this software.
It is noted that this issue only affects PowerLinkT WAN Aggregator running firmware 1.7.3.1. Newer revisions are not affected. Users should contact the vendor for information about obtaining upgrades if they are affected by the vulnerability.
Boa Webserver 0.92 r
-
Boa Boa Webserver Version 0.94.13
http://www.boa.org/boa-0.94.13.tar.gz
References
Boa Webserver File Disclosure Vulnerability
References:
References:
- Boa Webserver Homepage (Boa)
- PowerLinkT WAN Aggregator Homepage (AstroCorp)
- PowerLink WAN Aggregator - Vunerability ("morning_wood"
) - Re: PowerLink WAN Aggregator - Vunerability ([email protected])