Reported April 26, 2001, by Joe Testa.
VERSION AFFECTED
-
WebXQ 2.1.204 for Windows 2000, Windows NT, and Windows 9x
DESCRIPTION
A
vulnerability
exists in WebXQ
that lets an attacker break out of the Web root by using relative paths. For
example, an attacker can gain access to files outside of the Web root directory
by connecting to a vulnerable host and issuing the command
http://<vulnerablehost>/./…/<file outside of Web root>.
VENDOR RESPONSE
The vendor, DataWizard Technologies, has released Version 2.1.205 to correct this vulnerability.
CREDIT
Discovered by Joe
Testa.
0 comments
Hide comments