Mailtraq ASP Script File Source Code Disclosure Vulnerability
BID:7814
Info
Mailtraq ASP Script File Source Code Disclosure Vulnerability
| Bugtraq ID: | 7814 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 04 2003 12:00AM |
| Updated: | Jun 04 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to Ziv Kamir <[email protected]>. |
| Vulnerable: |
Fastraq Mailtraq 2.2 |
| Not Vulnerable: | |
Discussion
Mailtraq ASP Script File Source Code Disclosure Vulnerability
A vulnerability has been reported in Mailtraq that may result in the disclosure of ASP script files' source code.
The vulnerability exists due to insufficient sanitization of HTTP requests to the vulnerable Mailtraq server.
A malicious attacker can append a '.' character to the end of requests. This will result in Mailtraq divulging the contents of the requested ASP script file.
A vulnerability has been reported in Mailtraq that may result in the disclosure of ASP script files' source code.
The vulnerability exists due to insufficient sanitization of HTTP requests to the vulnerable Mailtraq server.
A malicious attacker can append a '.' character to the end of requests. This will result in Mailtraq divulging the contents of the requested ASP script file.
Exploit / POC
Mailtraq ASP Script File Source Code Disclosure Vulnerability
This vulnerability can be exploited with a web browser.
This vulnerability can be exploited with a web browser.
Solution / Fix
Mailtraq ASP Script File Source Code Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.