SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Generic)  >   PJreview_Neo.cgi Vendors:   Power Ju live world
PJreview_Neo.cgi Input Validation Hole Discloses Files to Remote Users
SecurityTracker Alert ID:  1008881
SecurityTracker URL:  http://securitytracker.com/id/1008881
CVE Reference:   GENERIC-MAP-NOMATCH   (Links to External Site)
Date:  Jan 29 2004
Impact:   Disclosure of system information, Disclosure of user information
Exploit Included:  Yes  

Description:   Zone-h Security Team reported an input validation flaw in the 'PJreview_Neo.cgi' script. A remote user can view files on the target system.

It is reported that the the script does not properly validate user-supplied input in the 'p' variable. A remote user can submit a specially crafted request containing '../' directory traversal characters to view arbitrary files on the target system with the privileges of the web service.

A demonstration exploit URL is provided:

http://address/directory/PJreview_Neo.cgi?p=/../../../../../../../../../../../../../../../../etc/passwd

Impact:   A remote user can view arbitrary files with the privileges of the web server.
Solution:   No solution was available at the time of this entry. The report indicates that the vendor's web site is no longer available.
Cause:   Access control error, Input validation error
Underlying OS:   Linux (Any), UNIX (Any), Windows (Any)

Message History:   None.


 Source Message Contents

Date:  Thu, 29 Jan 2004 11:43:23 +0100
Subject:  ZH2004-02SA (security advisory): PJ CGI Neo review (NeoBoard review)


ZH2004-02SA (security advisory): PJ CGI Neo review (NeoBoard review) Remote arbitrary file retrieving

Published: 29 january 2004

Released: 29 january 2004

Name: PJ CGI Neo review (NeoBoard review)

Affected Systems: Current version

Issue: Remote file retrieving

Author: Zone-h Security Labs

Vendor: http://www.livepj.com


Description

***********

Zone-h Security Team has discovered a flaw in PJ CGI Neo review (NeoBoard review). There 
is a vulnerability in the current version of NeoBoard that allows an attacker to retrieve 
arbitrary files from the webserver with its priviledges.



Details

*******


It's possibile for a remote attacker to retrieve any file from a webserver.

For example try this:

http://address/directory/PJreview_Neo.cgi?p=/../../../../../../../../../../../../../../../../etc/passwd




Solution:

*********

The vendor has not been contacted because his site is unreachable.



Suggestions:

************

Filter the "p" variable.



Zone-h Security Labs - zetalabs@zone-h.org


http://www.zone-h.org/advisories/read/id=3824



 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2012, SecurityGlobal.net LLC