Korean
<< Back
VID 21601
Severity 40
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The WebAPP software, according to its version number, has an unspecified file disclosure vulnerability. WebAPP is a freely available, open source Web portal system written in Perl for Unix operating systems. WebAPP version 0.9.9.2 and earlier versions could allow a remote attacker to view the contents of certain files, caused by an unspecified vulnerability. A remote attacker could exploit this vulnerability to obtain the contents of various files.

* Note: This check solely relied on the version number of the WebAPP software installed on the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=195
http://secunia.com/advisories/14716/

* Platforms Affected:
WebAPP version 0.9.9.2 and earlier versions
Unix Any version
Recommendation Apply the March 2005 Security Update for this vulnerability, available from the SourceForge.net Web site at http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=195
Related URL CVE-2005-0927 (CVE)
Related URL 12938 (SecurityFocus)
Related URL 19888 (ISS)