FreeProxy Input Validation Flaw Discloses Files to Remote Users
|
|
SecurityTracker Alert ID: 1008661 |
|
SecurityTracker URL: http://securitytracker.com/id/1008661
|
|
CVE Reference:
GENERIC-MAP-NOMATCH
(Links to External Site)
|
Updated: Jan 13 2004
|
Original Entry Date: Jan 9 2004
|
Impact:
Denial of service via network, Disclosure of system information, Disclosure of user information
|
Fix Available: Yes Vendor Confirmed: Yes Exploit Included: Yes
|
Version(s): 3.61
|
Description:
Some vulnerabilities were reported in FreeProxy in the FreeWeb component. A remote user can view files on the target system. A remote user can cause the application to crash.
badpack3t from SP Research Labs reported that a flaw in the built-in web server component allows a remote user to make an HTTP GET request containing '../' directory traversal characters to view files on the target system. A demonstration exploit request is provided:
GET /../../../../../../../boot.ini%00.html HTTP/1.0
It is also reported that a remote user can make a request for the 'CreateFile' function to cause the application to crash. A demonstration exploit request is provided:
GET CreateFile HTTP/1.0
Only the web server component of FreeProxy is vulnerable. The proxy itself is not affected.
The original advisory is available at:
http://www.security-protocols.com/modules.php?name=News&file=article&sid=1691&mode=&order=0&thold=0
|
Impact:
A remote user can view files on the target system that are located outside of the web document directory.
A remote user can cause the application to crash.
|
Solution:
The vendor released a fixed version of FreeProxy V3.61 ("build: Jan 9 2004 at 21:39:21"), available at:
http://www.alphalink.com.au/~gregr/freeproxy.zip
http://www.alphalink.com.au/~gregr/freeproxy.htm
|
Vendor URL: www.alphalink.com.au/~gregr/freeproxy.htm (Links to External Site)
|
Cause:
Exception handling error, Input validation error
|
Underlying OS:
Windows (NT), Windows (98), Windows (2000), Windows (2003), Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|