GWeb HTTP Server Directory Traversal Vulnerability
BID:9742
Info
GWeb HTTP Server Directory Traversal Vulnerability
| Bugtraq ID: | 9742 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0349 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2004 12:00AM |
| Updated: | Jul 12 2009 03:06AM |
| Credit: | Disclosure of this issue is credited to "Donato Ferrante" <[email protected]>. |
| Vulnerable: |
GWeb HTTP Server 0.6 GWeb HTTP Server 0.5 GameSpy Software Development Kit |
| Not Vulnerable: | |
Discussion
GWeb HTTP Server Directory Traversal Vulnerability
It has been reported that GWeb is prone to a directory traversal vulnerability. The issue is due to the server's failure to properly validate user supplied http requests.
This issue may allow an attacker to escape the web server root directory and view any web server readable files. Information acquired by exploiting this issue may be used to aid further attacks against a vulnerable system.
It has been reported that GWeb is prone to a directory traversal vulnerability. The issue is due to the server's failure to properly validate user supplied http requests.
This issue may allow an attacker to escape the web server root directory and view any web server readable files. Information acquired by exploiting this issue may be used to aid further attacks against a vulnerable system.
Exploit / POC
GWeb HTTP Server Directory Traversal Vulnerability
No exploit is required to leverage this issue. The following proof of concept has been provided:
http://www.example.com/../../../../../../windows/system.ini
No exploit is required to leverage this issue. The following proof of concept has been provided:
http://www.example.com/../../../../../../windows/system.ini
Solution / Fix
GWeb HTTP Server Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
GWeb HTTP Server Directory Traversal Vulnerability
References:
References:
- HTTP Server Home Page (GWeb)
- Vendor Home Page (GameSpy)
- Hidden Gamespy code leads to vulnerabilities in diffused games (Luigi Auriemma
)