OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[sec-adv] silentThought Simple Web Server Directory Traversal Vulnerability

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Fri Jun 13 2003 - 04:20:38 CDT


TITLE:
silentThought Simple Web Server Directory Traversal Vulnerability

READ ONLINE:
http://www.secunia.com/advisories/9020/

CRITICAL:

IMPACT:
Exposure of system information, Exposure of sensitive information

WHERE:
From remote

SOFTWARE:
silentThought Simple Web Server 1.x

DESCRIPTION:
silentThought Simple Web Server fails to check input properly in HTTP
GET requests. This allows malicious people to perform directory
traversals by including "../" in a request to the web server.

Example:
http://[victim]/../../winnt/repair/sam._

The vulnerability has been reported in version 1.0.

SOLUTION:
Filter "../" and other potentially malicious requests in a proxy or
firewall with URL filtering capabilities.

Install silentThought Simple Web Server's web root at a separate
partition.

REPORTED BY / CREDITS:
Ziv Kamir

----------------------------------------------------------------------

Secunia recommends that you verify all advisories you receive, by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

Contact details:
Web : http://www.secunia.com/
E-mail : supportsecunia.com
Tel : +44 (0) 20 7016 2693
Fax : +44 (0) 20 7637 0419

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------