179
WebAPP 0.9.9 index.cgi Directory Traversal
CGI
2004/09/08
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/14
2.0
Corrected the plugin structure and added the accuracy values in 1.1. Improved the pattern matching and introduced the plugin changelog in 2.0
tcp
80
open|send GET /index.cgi?action=topics&viewcat=../../../../../../../etc/passwd HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/#.# ### *root:*
99
Check is inspired by the Nessus plugin.
Jérôme Athias
jerome dot athias at caramail dot com
2004/08/30
http://www.securityfocus.com/archive/1/372731
WebAPP 0.9.9
WebAPP newer than 0.9.9 or other solutions
Directory Traversal
The remote host is running WebAPP, an open-source web portal application written in perl. There is a bug in index.cgi of version 0.9.9 which makes it vulnerable to directory traversal attacks. An attacker may use this bug to fetch files from the target system.
You should install or upgrade the software to the latest version. See http://www.web-app.org for more details. Also limit unwanted connections and communications with firewalling if possible.
Approx. 1 hour
Yes
http://www.securityfocus.com/bid/11028/exploit/
Yes
Yes
High
6
7
8
7
Medium
Nessus is able to do the same check. The possibilities of exploiting this kind of vulnerabilities is well-known and well documented.
11028
14365
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.computec.ch