InfronTech WebTide Directory/File Disclosure Vulnerability
BID:8909
Info
InfronTech WebTide Directory/File Disclosure Vulnerability
| Bugtraq ID: | 8909 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 28 2003 12:00AM |
| Updated: | Oct 28 2003 12:00AM |
| Credit: | Discovery is credited to SSR Team <[email protected]>. |
| Vulnerable: |
Infrontech WebTide 7.0 4 |
| Not Vulnerable: |
Infrontech WebTide 7.0 5 |
Discussion
InfronTech WebTide Directory/File Disclosure Vulnerability
Infrontech WebTide is prone to a vulnerability that may permit remote attackers to gain access to sensitive information. In particular, by submitting a request for '%3f.jsp', it is possible to list directory contents. It has also been reported that file contents, such as script source code, may also be disclosed in this manner.
Infrontech WebTide is prone to a vulnerability that may permit remote attackers to gain access to sensitive information. In particular, by submitting a request for '%3f.jsp', it is possible to list directory contents. It has also been reported that file contents, such as script source code, may also be disclosed in this manner.
Exploit / POC
InfronTech WebTide Directory/File Disclosure Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
InfronTech WebTide Directory/File Disclosure Vulnerability
Solution:
This issue has been reportedly addressed in WebTide version 7.05. Users should contact the vendor to obtain upgrades.
Solution:
This issue has been reportedly addressed in WebTide version 7.05. Users should contact the vendor to obtain upgrades.
References
InfronTech WebTide Directory/File Disclosure Vulnerability
References:
References:
- WebTide Homepage (Infrontech)