Korean
<< Back
VID 21394
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The Turbo Seek program is vulnerable to an information disclosure vulnerability.
Turbo Seek provides the capability to create and run a directory and search engine with ease, and is a shareware program designed to handle hundreds of thousands of listings and hundreds of categories for Unix and Linux-based operating systems. Turbo Seek versions prior to 1.7.2 could be exploited by remote attacker to disclose the content of arbitrary files, caused by improper handling of user-supplied input in the 'location' variable of the tseekdir.cgi script. A remote attacker could exploit this flaw to view the content of sensitive files on a system by appending a NULL byte ('%00') at the end of a requested filename.

* References:
http://www.osvdb.org/displayvuln.php?osvdb_id=9900
http://secunia.com/advisories/12500/
http://packetstormsecurity.nl/0409-exploits/adv17.txt

* Platforms Affected:
Focal Media, Turbo Seek prior to 1.7.2
Linux Any version
Unix Any version
Recommendation Upgrade to the latest version of Turbo Seek (1.7.2 or later), available from the Turbo Seek Download Web page at http://www.focalmedia.net/tbdownload.html
Related URL (CVE)
Related URL 11163 (SecurityFocus)
Related URL 17322 (ISS)