Korean
<< Back
VID 21600
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The WebAPP software is vulnerable to a directory traversal vulnerability in the index.cgi script. WebAPP is a freely available, open source Web portal system written in Perl for Unix operating systems. WebAPP version 0.9.9.1 and earlier versions could allow a remote attacker to view files residing outside of the Web root, caused by improper filtering of user-supplied input passed to the 'viewcat' parameter of the 'index.cgi' script. By sending a specially-crafted URL containing "dot dot" sequences (/../), a remote attacker could traverse directories and view any file on the Web server.

* References:
http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=184
http://marc.theaimsgroup.com/?l=bugtraq&m=109336268002879&w=2
http://secunia.com/advisories/12373

* Platforms Affected:
WebAPP version 0.9.9.1 and earlier versions
Unix Any version
Recommendation Upgrade to the latest version of WebAPP (0.9.9.2 or later), available from the WebAPP Download Web site at http://www.web-app.org/cgi-bin/index.cgi?action=downloads
Related URL CVE-2004-1742 (CVE)
Related URL 11028 (SecurityFocus)
Related URL 17100 (ISS)