179 WebAPP 0.9.9 index.cgi Directory Traversal CGI 2004/09/08 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/14 2.0 Corrected the plugin structure and added the accuracy values in 1.1. Improved the pattern matching and introduced the plugin changelog in 2.0 tcp 80 open|send GET /index.cgi?action=topics&viewcat=../../../../../../../etc/passwd HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/#.# ### *root:* 99 Check is inspired by the Nessus plugin. Jérôme Athias jerome dot athias at caramail dot com 2004/08/30 http://www.securityfocus.com/archive/1/372731 WebAPP 0.9.9 WebAPP newer than 0.9.9 or other solutions Directory Traversal The remote host is running WebAPP, an open-source web portal application written in perl. There is a bug in index.cgi of version 0.9.9 which makes it vulnerable to directory traversal attacks. An attacker may use this bug to fetch files from the target system. You should install or upgrade the software to the latest version. See http://www.web-app.org for more details. Also limit unwanted connections and communications with firewalling if possible. Approx. 1 hour Yes http://www.securityfocus.com/bid/11028/exploit/ Yes Yes High 6 7 8 7 Medium Nessus is able to do the same check. The possibilities of exploiting this kind of vulnerabilities is well-known and well documented. 11028 14365 Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427 http://www.computec.ch