|
|
Info |
Last Modified |
| about 1 year ago |
|
|
|
|
|
Description |
AN HTTPD Server contains a flaw that may allow a remote attacker to inject arbitrary text into the server log. The issue is due to the server not properly sanitizing the CR and LF characters of the URI being processed. Using a specially crafted URI, an attacker can cause the injection of custom lines into the log. This could be used to inject fake browsing entries, or arbitrary commands which can be executed through the cmdIS.DLL module.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
|
|
Solution |
Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround: Move httpd.log outside document root directory
|
|
Products |
|
AN HTTP Server
 |
1.42n |
|
|
|
|
Credit |
- Tan Chew Keong - vuln
secunia.com - Secunia Research
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|