Whale Communications e-Gap Security Appliance Login Page Source Code Disclosure Vulnerability
BID:9431
Info
Whale Communications e-Gap Security Appliance Login Page Source Code Disclosure Vulnerability
| Bugtraq ID: | 9431 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2004 12:00AM |
| Updated: | Jan 15 2004 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to ProCheckUp. |
| Vulnerable: |
Whale Communications e-Gap Appliance 2.5 |
| Not Vulnerable: | |
Discussion
Whale Communications e-Gap Security Appliance Login Page Source Code Disclosure Vulnerability
The e-GAP appliance has been reported prone to a source code disclosure vulnerability. It has been reported that, when the affected appliance handles unexpected HTTP requests it may divulge the source code of the login script. The login page is used to build a simple form for collecting and submitting the username and the password to the e-Gap server. The authentication logic is not part of this page and cannot be viewed by the attacker. The information contained in the login page is not typically sensitive.
The e-GAP appliance has been reported prone to a source code disclosure vulnerability. It has been reported that, when the affected appliance handles unexpected HTTP requests it may divulge the source code of the login script. The login page is used to build a simple form for collecting and submitting the username and the password to the e-Gap server. The authentication logic is not part of this page and cannot be viewed by the attacker. The information contained in the login page is not typically sensitive.
Exploit / POC
Whale Communications e-Gap Security Appliance Login Page Source Code Disclosure Vulnerability
The following proof of concept has been supplied:
TRACE / HTTP/1.0
The following proof of concept has been supplied:
TRACE / HTTP/1.0
Solution / Fix
Whale Communications e-Gap Security Appliance Login Page Source Code Disclosure Vulnerability
Solution:
It has been reported that the vendor has made patches to address this issue available. Customers are advised to contact the vendor for further details regarding obtaining and applying the relative patch.
Solution:
It has been reported that the vendor has made patches to address this issue available. Customers are advised to contact the vendor for further details regarding obtaining and applying the relative patch.
References
Whale Communications e-Gap Security Appliance Login Page Source Code Disclosure Vulnerability
References:
References:
- The e-Gap Product Suite (Whale Communications)
- ProCheckUp Security Bulletin PR03-07 (ProCheckUp)