Unauthorized File Disclosure in Deerfield WebSite Pro 3.1.11.0

A vulnerability exists in Deerfield’s WebSite Pro 3.1.11.0 that can disclose source-script code to an unauthorized user.

Ken Pfeil

May 28, 2002

2 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported May 20, 2002, by Ory Segal.

VERSION AFFECTED

·       Deerfield’s WebSite Pro 3.1.11.0

 

 

DESCRIPTION
Avulnerability exists in Deerfield’s WebSite Pro 3.1.11.0 that can disclosesource-script code to an unauthorized user. This condition appearswhen the software attempts to serve files with at least a four-characterextension (such as .shtml), which it requests by using 8.3 format filenames.

 

VENDOR RESPONSE

Deerfield hasreleased version 3.1.13.0,which fixes this vulnerability.

 

CREDIT
Discovered by OrySegal.

Reported May 20, 2002, by Ory Segal.

VERSION AFFECTED

·       Deerfield’s WebSite Pro 3.1.11.0

 

 

DESCRIPTION
Avulnerability exists in Deerfield’s WebSite Pro 3.1.11.0 that can disclosesource-script code to an unauthorized user. This condition appearswhen the software attempts to serve files with at least a four-characterextension (such as .shtml), which it requests by using 8.3 format filenames.

 

VENDOR RESPONSE

Deerfield hasreleased version 3.1.13.0,which fixes this vulnerability.

 

CREDIT
Discovered by OrySegal.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like