| VID |
21600 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The WebAPP software is vulnerable to a directory traversal vulnerability in the index.cgi script. WebAPP is a freely available, open source Web portal system written in Perl for Unix operating systems. WebAPP version 0.9.9.1 and earlier versions could allow a remote attacker to view files residing outside of the Web root, caused by improper filtering of user-supplied input passed to the 'viewcat' parameter of the 'index.cgi' script. By sending a specially-crafted URL containing "dot dot" sequences (/../), a remote attacker could traverse directories and view any file on the Web server.
* References: http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=184 http://marc.theaimsgroup.com/?l=bugtraq&m=109336268002879&w=2 http://secunia.com/advisories/12373
* Platforms Affected: WebAPP version 0.9.9.1 and earlier versions Unix Any version |
| Recommendation |
Upgrade to the latest version of WebAPP (0.9.9.2 or later), available from the WebAPP Download Web site at http://www.web-app.org/cgi-bin/index.cgi?action=downloads |
| Related URL |
CVE-2004-1742 (CVE) |
| Related URL |
11028 (SecurityFocus) |
| Related URL |
17100 (ISS) |
|