|
 |
|
 |
|
Pablo Software Solutions Baby Web Server Directory Traversal Vulnerability
|
|
 |
|
 |
Overview
Pablo Software Solutions Baby Web Server version 1.51 shows files and directories that reside outside the normal web root directory.
Discovered on 2003, July, 1st
Vendor: Pablo Software Solutions
Pablo's Baby Web Server is a multi threaded web server for Windows 98/NT/2k/XP.
This web server can shows file and directory content that reside outside the normal FTP root directory.
Risk
| Exploit easiness |
     |
| Vulnerability spreading |
     |
| Impact |
     |
| Risk |
     |
Details
The vulnerability can be done using any browser. You just have to send a dot-dot URL to retreive any file outside of the root directory.
Exploit
Here is an example of the vulnerability. The query sent was /../../../../../../winnt/system32/eula.txt :
Solution
The vendor has been informed and has solved the problem.
Download Pablo's Baby Web Server 1.52.
Discovered by
Arnaud Jacques aka scrap
webmaster@securiteinfo.com
http://www.securiteinfo.com
|
|