Etype Eserv Directory Traversal Vulnerability
BID:773
Info
Etype Eserv Directory Traversal Vulnerability
| Bugtraq ID: | 773 |
| Class: | Input Validation Error |
| CVE: |
CVE-1999-1509 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 04 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | Posted to bugtraq by Ussr Labs <[email protected]> on November 4, 1999. |
| Vulnerable: |
Etype Eserv 2.50 |
| Not Vulnerable: | |
Discussion
Etype Eserv Directory Traversal Vulnerability
Etype's Eserv product is designed to be a one-source internet connectivity solution, incorporating mail, web, ftp, and proxy servers into one package. The web server will allow remote browsing of the entire filesystem by the usage of ../ strings in the URL. This gives an attacker read access to every file on the server's filesystem that the webserver has access to.
Etype's Eserv product is designed to be a one-source internet connectivity solution, incorporating mail, web, ftp, and proxy servers into one package. The web server will allow remote browsing of the entire filesystem by the usage of ../ strings in the URL. This gives an attacker read access to every file on the server's filesystem that the webserver has access to.
Exploit / POC
Etype Eserv Directory Traversal Vulnerability
http://victim.com/../../../autoexec.bat
http://victim.com/../../../autoexec.bat
Solution / Fix
Etype Eserv Directory Traversal Vulnerability
Solution:
A new version of Eserv is available at:
ftp://ftp.eserv.ru/pub/
Solution:
A new version of Eserv is available at:
ftp://ftp.eserv.ru/pub/