| VID |
22373 |
| Severity |
30 |
| Port |
8081 |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The Yawcam software is vulnerable to a directory traversal vulnerability. Yawcam is a yet another web cam software for Windows operating systems. Yawcam version 0.2.5 could allow a remote attacker to traverse directories and view files residing outside of the Web root. By sending a specially-crafted URL containing "dot dot" sequences (../), a remote attacker could read arbitrary files outside of the web root directory with the privileges of the Web service.
* References: http://archives.neohapsis.com/archives/bugtraq/2005-04/0325.html http://www.securiteam.com/securitynews/5WP0L1FFFC.html
* Platforms Affected: Magnus Lundvall, Yawcam 0.2.5 Microsoft Windows Any version |
| Recommendation |
Upgrade to the latest version of Yawcam (0.2.6 or later), available from the Yawcam Web page at http://www.yawcam.com/ |
| Related URL |
CVE-2005-1230 (CVE) |
| Related URL |
13295 (SecurityFocus) |
| Related URL |
20224 (ISS) |
|