Lotus Domino Allows Directory Traversal

Lotus Domino Server lets remote users gain access to files not typically available through the server.

ITPro Today

January 8, 2001

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported January 5, 2001by Georgi Guninski

VERSIONS AFFECTED

  • Lotus Domino 5.0.6

DESCRIPTION

LotusDomino Server lets remote users gain access to files not typically availablethrough the server.

DEMONSTRATION

Byinserting an .nfs extension into the URL after the server name, remote users can specify a filename for viewing, provided they know theliteral path to the file:

http://localhost/.nsf/../winnt/win.ini

VENDORRESPONSE

IBMhas been informed of the problem and will correct the matter in the next versionof Domino Server. In the meantime, users can work around the problem by creatinga URL redirection or mapping within the Domino Server administrative client, andby isolating the Domino Server installation on its own partition.

UPDATE 01/18/2001: According to a response posted on the Lotus Web site, this issue will be corrected in version 5.0.6a.

CREDIT
Discovered by Georgi Guninski

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like