2201 : iWeb Server Directory Transversal
Printer | http://osvdb.org/2201 | Email This | Edit Vulnerability

Views This Week Views All Time Added to OSVDB Last Modified Modified (since 2008) Percent Complete
5 525 almost 10 years ago over 5 years ago 0 times 10%

This Entry needs help! It is only 10% Complete. Click the edit link above to add more information.

Contributing is fast and easy, and benefits the entire security community.

Timeline

Disclosure Date
2003-06-23

Description

TA-2003-06 Directory Transversal Vulnerability in iWeb Server 2 contributed by: rushjo ====================================================================================== Tripbit Security Advisory TA-2003-06 Directory Transversal Vulnerability in iWeb Server 2 ====================================================================================== PROGRAM: iWeb Server 2 HOMEPAGE: http://www.ashleybrown.co.uk/iweb/ VULNERABLE VERSIONS: 2 RISK: High/Medium IMPACT: Directory Transversal Vulnerability RELEASE DATE: 2003-06 ====================================================================================== TABLE OF CONTENTS ====================================================================================== 1..........................................................DESCRIPTION 2..............................................................DETAILS 3............................................................SOLUTIONS 4........................................................VENDOR STATUS 5..............................................................CREDITS 6...........................................................DISCLAIMER 7...........................................................REFERENCES 8.............................................................FEEDBACK 1. DESCRIPTION ====================================================================================== "The iWeb Mini Web Server is a mini web server designed for use on Intranets and for testing websites in a realistic environment." (This description is taken from the website of Ashley Brown) 2. DETAILS ====================================================================================== - Directory Transversal Vulnerability: There is an other Directory Transversal Vulnerability in iWeb Server which allows an remote attackers to see the content of the requested file. for example: http://host/%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindowssystem.ini 3. SOLUTIONS ====================================================================================== No solution for the moment. 5. VENDOR STATUS ====================================================================================== The vendor has reportedly been notified. But the vendor told us that is an old bug. We don't think so. 6. CREDITS ====================================================================================== Discovered by posidron 7. DISLAIMER ====================================================================================== The information within this paper may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties with regard to this information. In no event shall the author be liable for any damages whatsoever arising out of or in connection with the use or spread of this information. Any use of this information is at the user's own risk. 8. REFERENCES ====================================================================================== - Original Version: http://www.tripbit.org 9. FEEDBACK ====================================================================================== Please send suggestions, updates, and comments to: Tripbit Security Advisory http://www.tripbit.org [email protected] [email protected]

Classification

Unknown or Incomplete

Products

Unknown or Incomplete

References

Credit

Unknown or Incomplete

CVSSv2 Score

NVD does not currently have a CVSSv2 score assigned.

Comments

No Comments.

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2002 - 2013 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use