BearShare File-Sharing Directory Traversal Vulnerability
A directory traversal vulnerability exists in the file-sharing program BearShare.
October 6, 2002
Reported October 4, 2002, bySecuriTeam.
VERSION AFFECTED
· BearShare 4.0.6 and 4.0.5
DESCRIPTION
A directory traversal vulnerability exists in thefile-sharing program BearShare. This vulnerability stems from a flaw in thepersonal Web-server portion of BearShare, which could let an attacker view anyfile on the vulnerable system by issuing a specially crafted HTTP request.
DEMONSTRATION
The discoverer posted the following demonstration asproof of concept:
Byissuing the following request,
http://127.0.0.1:6346/%5c..%5c..%5c..%5cwindows%5cwin.ini
wouldreturn the contents of the win.ini file.
VENDOR RESPONSE
Thevendor, Free Peers, has released version4.0.6 to address the traversal issue described above, but the software is stillvulnerable if an attacker uses an HTTP request such as
http://127.0.0.1:6346/%5c..%5c..%5c..%5cwindows%5cwin%2eini.Free Peers has not yet addressed this second variant of the same problem.
CREDIT
Discovered byGluck and MarioSolares.
About the Author
You May Also Like