PY Software Active Webcam Webserver Directory Traversal Vulnerability
BID:9260
Info
PY Software Active Webcam Webserver Directory Traversal Vulnerability
| Bugtraq ID: | 9260 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2003 12:00AM |
| Updated: | Dec 19 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Luigi Auriemma <[email protected]>. |
| Vulnerable: |
PY Software Active WebCam 4.3 |
| Not Vulnerable: |
PY Software Active WebCam 4.3 |
Discussion
PY Software Active Webcam Webserver Directory Traversal Vulnerability
It has been reported that Active Webcam webserver may be prone to a directory traversal vulnerability that may allow a remote attacker to gain access to sensitive information, which may be used to launch further attacks against a vulnerable system. The attacker may traverse outside the server root directory by using '../' or '..\' character sequences.
Active Webcam webserver versions 4.3 and prior released before December 17, 2003 are reported to be prone to this issue.
It has been reported that Active Webcam webserver may be prone to a directory traversal vulnerability that may allow a remote attacker to gain access to sensitive information, which may be used to launch further attacks against a vulnerable system. The attacker may traverse outside the server root directory by using '../' or '..\' character sequences.
Active Webcam webserver versions 4.3 and prior released before December 17, 2003 are reported to be prone to this issue.
Exploit / POC
PY Software Active Webcam Webserver Directory Traversal Vulnerability
The following proof of concept has been provided:
http://www.example.com/../../../windows/system.ini
http://www.example.com/..\..\..\windows/system.ini
The following proof of concept has been provided:
http://www.example.com/../../../windows/system.ini
http://www.example.com/..\..\..\windows/system.ini
Solution / Fix
PY Software Active Webcam Webserver Directory Traversal Vulnerability
Solution:
The vendor has released a patched version of the software. It has been reported that Active Webcam version 4.3 released after December 17, 2003 is not vulnerable to this issue.
Solution:
The vendor has released a patched version of the software. It has been reported that Active Webcam version 4.3 released after December 17, 2003 is not vulnerable to this issue.
References
PY Software Active Webcam Webserver Directory Traversal Vulnerability
References:
References:
- Active Webcam Product Page (PY Software)
- Directory traversal and XSS in Active Webcam <= 4.3 (Luigi Auriemma
)