Snowblind Web Server File Disclosure Vulnerability
BID:7618
Info
Snowblind Web Server File Disclosure Vulnerability
| Bugtraq ID: | 7618 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 16 2003 12:00AM |
| Updated: | May 16 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "euronymous" <[email protected]>. |
| Vulnerable: |
Snowblind Web Server 1.1 Snowblind Web Server 1.0 |
| Not Vulnerable: | |
Discussion
Snowblind Web Server File Disclosure Vulnerability
It has been announced that Snowblind Web Server is vulnerable to a condition that may result in the disclosure of potentially sensitive information.
According to the report, Snowblind Web Server does not perform correct access validation on client requested paths which include "../" character sequences.
It has been announced that Snowblind Web Server is vulnerable to a condition that may result in the disclosure of potentially sensitive information.
According to the report, Snowblind Web Server does not perform correct access validation on client requested paths which include "../" character sequences.
Exploit / POC
Snowblind Web Server File Disclosure Vulnerability
The following proof of concept has been supplied:
http://www.example.com/../../windows/system.ini
http://www.example.com/internal.sws?../../windows/system.ini
The following proof of concept has been supplied:
http://www.example.com/../../windows/system.ini
http://www.example.com/internal.sws?../../windows/system.ini