Vulnerability Note VU#146704
Hyperseek 2000 hsx.cgi does not adequately filter user input disclosing directory listings and file contents
OverviewiWeb Systems Hyperseek search engine may allow malformed URL requests to access files outside the document root of a vulnerable system.
I. DescriptionA specially crafted URL can disclose the directory listing and files of the target system with read permissions.II. ImpactRemote attackers may be able to disclose directory listings and files of the target system with read permissions.III. SolutionContact the vendor to obtain a patch.
Systems Affected
References
http://www.securityfocus.com/bid/2314
http://www.hyperseek.com/hyperseek/
Credit
Mc GaN <vipersv@mail.ru>, has been publicly credited for discovering this vulnerability.
This document was written by Ian A. Finlay.
Other Information
| Date Public | 01/28/2001 |
| Date First Published | 02/14/2003 03:41:49 PM |
| Date Last Updated | 02/14/2003 |
| CERT Advisory | |
| CVE Name | CAN-2001-0253 |
| Metric | 4.50 |
| Document Revision | 18 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|