Apple QuickTime/Darwin Streaming Server parse_xml.cgi Source Disclosure Vulnerability
BID:8256
Info
Apple QuickTime/Darwin Streaming Server parse_xml.cgi Source Disclosure Vulnerability
| Bugtraq ID: | 8256 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0423 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2003 12:00AM |
| Updated: | Mar 19 2015 08:11AM |
| Credit: | Discovery is credited to Rapid7. |
| Vulnerable: |
Apple Darwin Streaming Server 4.1.3 |
| Not Vulnerable: | |
Discussion
Apple QuickTime/Darwin Streaming Server parse_xml.cgi Source Disclosure Vulnerability
Apple QuickTime/Darwin Streaming Server is prone to a source disclosure issue. The issue exists in the parse_xml.cgi administrative script. This could permit an attacker to gain access to sensitive information contained within script source code.
This issue is reported to affect versions up to and including 4.1.3g.
Apple QuickTime/Darwin Streaming Server is prone to a source disclosure issue. The issue exists in the parse_xml.cgi administrative script. This could permit an attacker to gain access to sensitive information contained within script source code.
This issue is reported to affect versions up to and including 4.1.3g.
Exploit / POC
Apple QuickTime/Darwin Streaming Server parse_xml.cgi Source Disclosure Vulnerability
This issue can be exploited with a web browser. The following example was provided:
http://www.example.com:1220/parse_xml.cgi?filename=[filename]
This issue can be exploited with a web browser. The following example was provided:
http://www.example.com:1220/parse_xml.cgi?filename=[filename]
Solution / Fix
Apple QuickTime/Darwin Streaming Server parse_xml.cgi Source Disclosure Vulnerability
Solution:
Apple is reported to currently be investigating this issue and has not confirmed its existence or stated that fixes are pending.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Apple is reported to currently be investigating this issue and has not confirmed its existence or stated that fixes are pending.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Apple QuickTime/Darwin Streaming Server parse_xml.cgi Source Disclosure Vulnerability
References:
References: