Softrex Tornado WWW-Server File Disclosure Vulnerability
BID:7715
Info
Softrex Tornado WWW-Server File Disclosure Vulnerability
| Bugtraq ID: | 7715 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2003 12:00AM |
| Updated: | May 28 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to D4rkGr3y <[email protected]>. |
| Vulnerable: |
Softrex Tornado www-Server 1.2 |
| Not Vulnerable: | |
Discussion
Softrex Tornado WWW-Server File Disclosure Vulnerability
It has been announced that Tornado www-Server is vulnerable to a condition that may result in the disclosure of potentially sensitive information.
According to the report, Tornado www-Server does not perform sufficient sanitization on client requested paths which include "../" character sequences.
It has been announced that Tornado www-Server is vulnerable to a condition that may result in the disclosure of potentially sensitive information.
According to the report, Tornado www-Server does not perform sufficient sanitization on client requested paths which include "../" character sequences.
Exploit / POC
Softrex Tornado WWW-Server File Disclosure Vulnerability
This vulnerability can be exploited with a web browser.
This vulnerability can be exploited with a web browser.
Solution / Fix
Softrex Tornado WWW-Server File Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Softrex Tornado WWW-Server File Disclosure Vulnerability
References:
References:
- Tornado www-Server (Softrex)
- Tornado www-server v1.2: directory traversal, buffer overflow (D4rkGr3y
)