Netauth Exposes File System

Netauth does not guard against the use of relative pathnames. By using the dot-dot-slash (../) syntax, directories can be nagivated to expose the content of files.

ITPro Today

August 16, 2000

1 Min Read
ITPro Today logo in a gray background | ITPro Today

 

Reported August 17, 2000 by eEye Digital Security

VERSIONS AFFECTED

  • Netauth 4.2b and earlier versions

DESCRIPTION

Netauth does not guard against the use of relative pathnames. By using the dot-dot-slash (../) syntax, directories can be nagivated to expose file content.

DEMONSTRATION

The following would expose the "passwd" file:

http://[server]/cgi-bin/netauth.cgi?cmd=show&page=../../../../../../../../../etc/passwd

VENDOR RESPONSE

NetWin released a new version which corrects this vulnerability along with other bugs.

CREDIT
Discovered by eEye Digital Security

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like