CERT home
vulnerabilities & fixesevaluations & practicesresearch & analysistraining & education
homesearchFAQsite indexcontact
Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information
 

 View Notes By
Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric

Vulnerability Note VU#146704

Hyperseek 2000 hsx.cgi does not adequately filter user input disclosing directory listings and file contents

Overview

iWeb Systems Hyperseek search engine may allow malformed URL requests to access files outside the document root of a vulnerable system.

I. Description

A specially crafted URL can disclose the directory listing and files of the target system with read permissions.

II. Impact

Remote attackers may be able to disclose directory listings and files of the target system with read permissions.

III. Solution

Contact the vendor to obtain a patch.

Systems Affected

VendorStatusDate Updated
IWeb SystemsVulnerable14-Feb-2003

References


http://www.securityfocus.com/bid/2314
http://www.hyperseek.com/hyperseek/

Credit

Mc GaN <vipersv@mail.ru>, has been publicly credited for discovering this vulnerability.

This document was written by Ian A. Finlay.

Other Information

Date Public01/28/2001
Date First Published02/14/2003 03:41:49 PM
Date Last Updated02/14/2003
CERT Advisory 
CVE NameCAN-2001-0253
Metric4.50
Document Revision18

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

Copyright 2003 Carnegie Mellon University