Methodus 3 Web Server File Disclosure Vulnerability
BID:7908
Info
Methodus 3 Web Server File Disclosure Vulnerability
| Bugtraq ID: | 7908 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 13 2003 12:00AM |
| Updated: | Jun 13 2003 12:00AM |
| Credit: | Discovery is credited to Peter Winter-Smith. |
| Vulnerable: |
Methodus Methodus 3 Build 9 |
| Not Vulnerable: | |
Discussion
Methodus 3 Web Server File Disclosure Vulnerability
The Methodus 3 Web Server component is prone to a file disclosure vulnerability. It is possible for remote attackers to retrieve resources outside of the web root directory via directory traversal attacks. This could potentially be exploited to gain access to sensitive files on a system hosting the vulnerable software.
The Methodus 3 Web Server component is prone to a file disclosure vulnerability. It is possible for remote attackers to retrieve resources outside of the web root directory via directory traversal attacks. This could potentially be exploited to gain access to sensitive files on a system hosting the vulnerable software.
Exploit / POC
Methodus 3 Web Server File Disclosure Vulnerability
This issue may be exploited with a web browser. The following example was provided:
http://www.example.com/../../../windows/win.ini
This issue may be exploited with a web browser. The following example was provided:
http://www.example.com/../../../windows/win.ini
Solution / Fix
Methodus 3 Web Server File Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.