FutureWave WebX Server Directory Traversal Vulnerability
BID:8583
Info
FutureWave WebX Server Directory Traversal Vulnerability
| Bugtraq ID: | 8583 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2003 12:00AM |
| Updated: | Sep 10 2003 12:00AM |
| Credit: | The disclosure of this vulnerability has been credited to dr_insane. |
| Vulnerable: |
FutureWave WebX Server 1.1 FutureWave WebX Lite |
| Not Vulnerable: | |
Discussion
FutureWave WebX Server Directory Traversal Vulnerability
It has been reported that FutureWave WebX Server may be prone to a directory traversal issue allow a remote attacker to traverse outside the server root directory in order to retrieve arbitrary files.
This vulnerablity may allow an attacker to gain access to sensitive data that may be used to launch further attacks.
It has been reported that FutureWave WebX Server may be prone to a directory traversal issue allow a remote attacker to traverse outside the server root directory in order to retrieve arbitrary files.
This vulnerablity may allow an attacker to gain access to sensitive data that may be used to launch further attacks.
Exploit / POC
FutureWave WebX Server Directory Traversal Vulnerability
The following proof of concept was provided:
http://[victim]/../../../anyfile
The following proof of concept was provided:
http://[victim]/../../../anyfile