EServ Directory Indexing Vulnerability
BID:7669
Info
EServ Directory Indexing Vulnerability
| Bugtraq ID: | 7669 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 23 2003 12:00AM |
| Updated: | May 23 2003 12:00AM |
| Credit: | Discovery of this issue is credited to D4rkGr3y <[email protected]>. |
| Vulnerable: |
Etype Eserv 2.99 Etype Eserv 2.98 Etype Eserv 2.97 Etype Eserv 2.96 Etype Eserv 2.95 |
| Not Vulnerable: | |
Discussion
EServ Directory Indexing Vulnerability
EServ does not sufficiently prevent web users from being able to view directory indexes. This may result in disclosure of sensitive information.
EServ does not sufficiently prevent web users from being able to view directory indexes. This may result in disclosure of sensitive information.
Exploit / POC
EServ Directory Indexing Vulnerability
The following example was provided:
GET /? HTTP/1.1
The following example was provided:
GET /? HTTP/1.1
Solution / Fix
EServ Directory Indexing Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
EServ Directory Indexing Vulnerability
References:
References:
- EServ Homepage (EServ)
- EServ/2.99: problems (D4rkGr3y
)