NetServe Web Server Directory Traversal Vulnerability
BID:9059
Info
NetServe Web Server Directory Traversal Vulnerability
| Bugtraq ID: | 9059 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 17 2003 12:00AM |
| Updated: | Nov 17 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to nimber <[email protected]>. |
| Vulnerable: |
Net-X Solutions NetServe Web Server 1.0.7 |
| Not Vulnerable: |
Net-X Solutions NetServe Web Server 1.0.9 Net-X Solutions NetServe Web Server 1.0.8 |
Discussion
NetServe Web Server Directory Traversal Vulnerability
It has been reported that NetServe may be prone to a directory traversal vulnerability that may allow an attacker to gain access to sensitive information. The issue presents itself due to insufficient sanitization of user-supplied input. An attacker may traverse outside the server root directory by using '../' character sequences.
NetServe Web Server version 1.0.7 is reported to be prone to this issue, however other versions may be affected as well.
It has been reported that NetServe may be prone to a directory traversal vulnerability that may allow an attacker to gain access to sensitive information. The issue presents itself due to insufficient sanitization of user-supplied input. An attacker may traverse outside the server root directory by using '../' character sequences.
NetServe Web Server version 1.0.7 is reported to be prone to this issue, however other versions may be affected as well.
Exploit / POC
NetServe Web Server Directory Traversal Vulnerability
The following proof of concept has been provided:
http://www.example.com/../test/test.txt
The following proof of concept has been provided:
http://www.example.com/../test/test.txt
Solution / Fix
NetServe Web Server Directory Traversal Vulnerability
Solution:
The vendor has reported that NetServe Web Server version 1.0.8 and above are not affected by this vulnerability. Affected users are advised to upgrade as soon as possible.
Net-X Solutions NetServe Web Server 1.0.7
Solution:
The vendor has reported that NetServe Web Server version 1.0.8 and above are not affected by this vulnerability. Affected users are advised to upgrade as soon as possible.
Net-X Solutions NetServe Web Server 1.0.7
-
Net-X Solutions NetServe Web Server Version 1.0.9
http://www.starlots.com/netx/index.html
References
NetServe Web Server Directory Traversal Vulnerability
References:
References:
- Product Homepage (Net-X Solutions)
- Multiple vulnerability in NetServe 1.0.7 (=?koi8-r?Q?=22?=nimber=?koi8-r?Q?=22=20?=
)