Unauthorized File Disclosure in Deerfield WebSite Pro 3.1.11.0
A vulnerability exists in Deerfield’s WebSite Pro 3.1.11.0 that can disclose source-script code to an unauthorized user.
May 28, 2002
Reported May 20, 2002, by Ory Segal.
VERSION AFFECTED
· Deerfield’s WebSite Pro 3.1.11.0
DESCRIPTION
Avulnerability exists in Deerfield’s WebSite Pro 3.1.11.0 that can disclosesource-script code to an unauthorized user. This condition appearswhen the software attempts to serve files with at least a four-characterextension (such as .shtml), which it requests by using 8.3 format filenames.
VENDOR RESPONSE
Deerfield hasreleased version 3.1.13.0,which fixes this vulnerability.
CREDIT
Discovered by OrySegal.
Reported May 20, 2002, by Ory Segal.
VERSION AFFECTED
· Deerfield’s WebSite Pro 3.1.11.0
DESCRIPTION
Avulnerability exists in Deerfield’s WebSite Pro 3.1.11.0 that can disclosesource-script code to an unauthorized user. This condition appearswhen the software attempts to serve files with at least a four-characterextension (such as .shtml), which it requests by using 8.3 format filenames.
VENDOR RESPONSE
Deerfield hasreleased version 3.1.13.0,which fixes this vulnerability.
CREDIT
Discovered by OrySegal.
About the Author
You May Also Like