GoAhead Webserver ASP Script File Source Code Disclosure Vulnerability
BID:9239
Info
GoAhead Webserver ASP Script File Source Code Disclosure Vulnerability
| Bugtraq ID: | 9239 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-1603 CVE-2009-0474 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2003 12:00AM |
| Updated: | Feb 19 2009 09:47PM |
| Credit: | Discovery of this vulnerability has been credited to Luigi Auriemma <[email protected]>. |
| Vulnerable: |
Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge 0 GoAhead Software GoAhead WebServer 2.1.7 GoAhead Software GoAhead WebServer 2.1.6 GoAhead Software GoAhead WebServer 2.1.5 GoAhead Software GoAhead WebServer 2.1.4 GoAhead Software GoAhead WebServer 2.1.3 GoAhead Software GoAhead WebServer 2.1.2 GoAhead Software GoAhead WebServer 2.1.1 GoAhead Software GoAhead WebServer 2.1 GoAhead Software GoAhead WebServer 2.0 |
| Not Vulnerable: |
GoAhead Software GoAhead WebServer 2.1.8 |
Discussion
GoAhead Webserver ASP Script File Source Code Disclosure Vulnerability
A vulnerability in GoAhead webserver may result in the disclosure of the source code of ASP script files. The vulnerability occurs because the application fails to sanitize HTTP requests.
An attacker can append certain characters to the end of an HTTP request for a specific ASP file. As a result, GoAhead webserver will disclose the contents of the requested ASP script file to the attacker.
This issue affects GoAhead 2.1.7 and earlier.
A vulnerability in GoAhead webserver may result in the disclosure of the source code of ASP script files. The vulnerability occurs because the application fails to sanitize HTTP requests.
An attacker can append certain characters to the end of an HTTP request for a specific ASP file. As a result, GoAhead webserver will disclose the contents of the requested ASP script file to the attacker.
This issue affects GoAhead 2.1.7 and earlier.
Exploit / POC
Solution / Fix
GoAhead Webserver ASP Script File Source Code Disclosure Vulnerability
Solution:
The vendor has released GoAhead 2.1.8 to address this issue. Contact the vendor for details.
Solution:
The vendor has released GoAhead 2.1.8 to address this issue. Contact the vendor for details.
References
GoAhead Webserver ASP Script File Source Code Disclosure Vulnerability
References:
References:
- ControlLogix 1756-ENTB/A Ethernet/IP Bridge - Potential Security Vulnerabilities (Rockwell Automation)
- GoAhead WebServer Product Homepage (GoAhead Software)
- Vulnerability Note VU#124059 GoAhead Webserver information disclosure vulnerabil (US-CERT)
- Vulnerability Note VU#975041 GoAhead Web Server discloses source code of ASP fil (CERT)
- Server side scripts viewing in Goahead webserver <= 2.1.7 (Luigi Auriemma
)