SurgeLDAP Path Disclosure Vulnerability
BID:8406
Info
SurgeLDAP Path Disclosure Vulnerability
| Bugtraq ID: | 8406 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 13 2003 12:00AM |
| Updated: | Aug 13 2003 12:00AM |
| Credit: | Discovery is credit to Ziv Kamir. |
| Vulnerable: |
NetWin SurgeLDAP 1.0 d |
| Not Vulnerable: |
NetWin SurgeLDAP 1.0 e |
Discussion
SurgeLDAP Path Disclosure Vulnerability
SurgeLDAP is prone to a path disclosure vulnerability. It is possible to gain access to sensitive path information by issuing an HTTP GET request for an invalid resource.
This issue exists in the web server component of SurgeLDAP.
SurgeLDAP is prone to a path disclosure vulnerability. It is possible to gain access to sensitive path information by issuing an HTTP GET request for an invalid resource.
This issue exists in the web server component of SurgeLDAP.
Exploit / POC
SurgeLDAP Path Disclosure Vulnerability
There is no exploit required. The following example was submitted:
http://www.example.com:6680/aaa.html
There is no exploit required. The following example was submitted:
http://www.example.com:6680/aaa.html
Solution / Fix
SurgeLDAP Path Disclosure Vulnerability
Solution:
The vendor has addressed this issue in SurgeLDAP 1.0e. Users are advised to upgrade as soon as possible.
NetWin SurgeLDAP 1.0 d
Solution:
The vendor has addressed this issue in SurgeLDAP 1.0e. Users are advised to upgrade as soon as possible.
NetWin SurgeLDAP 1.0 d
-
NetWin SurgeLDAP 1.0e
http://netwinsite.com/cgi-bin/keycgi.exe?cmd=download&product=surgelda p
References
SurgeLDAP Path Disclosure Vulnerability
References:
References:
- SurgeLDAP Homepage (NetWin)
- SurgeLDAP Update Information Page (NetWin)