VID |
22373 |
Severity |
30 |
Port |
8081 |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
The Yawcam software is vulnerable to a directory traversal vulnerability. Yawcam is a yet another web cam software for Windows operating systems. Yawcam version 0.2.5 could allow a remote attacker to traverse directories and view files residing outside of the Web root. By sending a specially-crafted URL containing "dot dot" sequences (../), a remote attacker could read arbitrary files outside of the web root directory with the privileges of the Web service.
* References: http://archives.neohapsis.com/archives/bugtraq/2005-04/0325.html http://www.securiteam.com/securitynews/5WP0L1FFFC.html
* Platforms Affected: Magnus Lundvall, Yawcam 0.2.5 Microsoft Windows Any version |
Recommendation |
Upgrade to the latest version of Yawcam (0.2.6 or later), available from the Yawcam Web page at http://www.yawcam.com/ |
Related URL |
CVE-2005-1230 (CVE) |
Related URL |
13295 (SecurityFocus) |
Related URL |
20224 (ISS) |
|