Ashley Brown iWeb Server Encoded Backslash Directory Traversal Vulnerability
BID:8943
Info
Ashley Brown iWeb Server Encoded Backslash Directory Traversal Vulnerability
| Bugtraq ID: | 8943 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2003 12:00AM |
| Updated: | Oct 31 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Chris from cr-secure.net. |
| Vulnerable: |
Ashley Brown iWeb Server |
| Not Vulnerable: | |
Discussion
Ashley Brown iWeb Server Encoded Backslash Directory Traversal Vulnerability
It has been reported that iWeb Server is prone a directory traversal issue allowing a remote attacker to traverse outside the server root directory by using '..%5C' character sequences.
Successful exploitation of this vulnerability may allow a remote attacker to gain access to sensitive information, which may be used to mount further attacks against a vulnerable system.
It has been reported that iWeb Server is prone a directory traversal issue allowing a remote attacker to traverse outside the server root directory by using '..%5C' character sequences.
Successful exploitation of this vulnerability may allow a remote attacker to gain access to sensitive information, which may be used to mount further attacks against a vulnerable system.
Exploit / POC
Ashley Brown iWeb Server Encoded Backslash Directory Traversal Vulnerability
The following proof of concept has been provided:
http://127.0.0.1/..%5C..%5C..%5C.. %5C..%5C..%5C/winnt/win.ini
http://127.0.0.1/..%5C..%5C..%5C..%5C..%5C..%5C/winnt/system32/registry.inf
The following proof of concept has been provided:
http://127.0.0.1/..%5C..%5C..%5C.. %5C..%5C..%5C/winnt/win.ini
http://127.0.0.1/..%5C..%5C..%5C..%5C..%5C..%5C/winnt/system32/registry.inf
Solution / Fix
Ashley Brown iWeb Server Encoded Backslash Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Ashley Brown iWeb Server Encoded Backslash Directory Traversal Vulnerability
References:
References:
- iWeb Server (Ashley Brown)