Korean
<< Back
VID 22373
Severity 30
Port 8081
Protocol TCP
Class CGI
Detailed Description The Yawcam software is vulnerable to a directory traversal vulnerability. Yawcam is a yet another web cam software for Windows operating systems. Yawcam version 0.2.5 could allow a remote attacker to traverse directories and view files residing outside of the Web root. By sending a specially-crafted URL containing "dot dot" sequences (../), a remote attacker could read arbitrary files outside of the web root directory with the privileges of the Web service.

* References:
http://archives.neohapsis.com/archives/bugtraq/2005-04/0325.html
http://www.securiteam.com/securitynews/5WP0L1FFFC.html

* Platforms Affected:
Magnus Lundvall, Yawcam 0.2.5
Microsoft Windows Any version
Recommendation Upgrade to the latest version of Yawcam (0.2.6 or later), available from the Yawcam Web page at http://www.yawcam.com/
Related URL CVE-2005-1230 (CVE)
Related URL 13295 (SecurityFocus)
Related URL 20224 (ISS)