Netauth Exposes File System
Netauth does not guard against the use of relative pathnames. By using the dot-dot-slash (../) syntax, directories can be nagivated to expose the content of files.
August 16, 2000
Reported August 17, 2000 by eEye Digital Security
VERSIONS AFFECTED
Netauth 4.2b and earlier versions
DESCRIPTION
Netauth does not guard against the use of relative pathnames. By using the dot-dot-slash (../) syntax, directories can be nagivated to expose file content.
DEMONSTRATION
The following would expose the "passwd" file:
http://[server]/cgi-bin/netauth.cgi?cmd=show&page=../../../../../../../../../etc/passwd
VENDOR RESPONSE
NetWin released a new version which corrects this vulnerability along with other bugs.
CREDIT
Discovered by eEye Digital Security
About the Author
You May Also Like