BearShare File-Sharing Directory Traversal Vulnerability

A directory traversal vulnerability exists in the file-sharing program BearShare.

Ken Pfeil

October 6, 2002

2 Min Read
ITPro Today logo

Reported October 4, 2002, bySecuriTeam.

VERSION AFFECTED

 

·        BearShare 4.0.6 and 4.0.5

 

DESCRIPTION

 

A directory traversal vulnerability exists in thefile-sharing program BearShare. This vulnerability stems from a flaw in thepersonal Web-server portion of BearShare, which could let an attacker view anyfile on the vulnerable system by issuing a specially crafted HTTP request.

 

 

DEMONSTRATION

 

The discoverer posted the following demonstration asproof of concept:

 

Byissuing the following request,

http://127.0.0.1:6346/%5c..%5c..%5c..%5cwindows%5cwin.ini

 

wouldreturn the contents of the win.ini file.

 

 

VENDOR RESPONSE

 

Thevendor, Free Peers, has released version4.0.6 to address the traversal issue described above, but the software is stillvulnerable if an attacker uses an HTTP request such as

http://127.0.0.1:6346/%5c..%5c..%5c..%5cwindows%5cwin%2eini.Free Peers has not yet addressed this second variant of the same problem.

 

CREDIT

Discovered byGluck and MarioSolares.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like