Search:     Advanced search
server monitoring

Plain Old Webserver URI Traversal Arbitrary File Access

Article ID: 24669
Last updated: 27 Jan, 2009
Views: 561
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

Plain Old Webserver URI Traversal Arbitrary File Access

This script is Copyright (C) 2007-2008 Tenable Network Security

FamilyCGI abuses
Plugin ID24669
Bugtraq ID22502
CVE IDCVE-2007-0872

Description:

Synopsis :

The remote web server is susceptible to a directory traversal attack.

Description :

The remote host is running Plain Old Webserver, a Firefox extension
that acts as a web server.

The version of Plain Old Webserver (pow) installed on the remote host
fails to sanitize the URL of directory traversal sequences. An
unauthenticated attacker can exploit this to read files on the
affected host subject to the permissions of the user id under which
Firefox runs.

See also :

http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0197.html

Solution :

Unknown at this time.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
This article was:   Helpful | Not Helpful
Prev   Next
Episodex Guestbook Multiple Vulnerabilities (Auth Bypass, XSS)     PHP Doc System index.php show Parameter Local File Inclusion