OSVDB ID: 20075

Title: Xerver Single Dot File Request Source Disclosure

Info

Disclosure

Oct 19, 2005

Discovery

Unknown

Dates

Exploit

Oct 19, 2005

Solution

Unknown

Description

Xerver contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a '.' is appended to the filename of the script in the URL, which will disclose the source code of the script resulting in a loss of confidentiality.

Classification

Location: Remote/Network Access Required
Attack Type: Information Disclosure
Impact: Loss of Confidentiality
Exploit: Exploit Available
OSVDB: Web Related

Solution

Upgrade to version 4.20 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Xerver

Xerver

4.17

References

Credit

  • Ziv Kamir - vulncodeBrand New Doo Dooyahoo.com -


Direct URL: http://osvdb.org/36218