|
|
|
Vulnerability Note VU#471075
4D WebServer does not adequately validate user input thereby allowing directory traversal
Overview4D WebServer does not properly validate HTTP requests, allowing directory traversal outside the root web directory.
I. Description4D WebServer versions 6.5.7 and earlier do not properly validate HTTP requests, allowing directory traversal outside the root web directory.II. ImpactRemote attackers can view any file on the filesystem with privileges of the web server.III. SolutionThe CERT/CC is currently unaware of a practical solution to this problem.Systems Affected
| Vendor | Status | Date Updated |
| 4D | Vulnerable | 23-Sep-2002 |
References
http://www.securityfocus.com/bid/3209
http://www.4d.com/
Credit
Thanks to KF for reporting this vulnerability.
This document was written by Shawn Van Ittersum.
Other Information
| Date Public | 08/20/2001 |
| Date First Published | 09/26/2002 05:54:42 PM |
| Date Last Updated | 09/26/2002 |
| CERT Advisory | |
| CVE Name | |
| Metric | 2.81 |
| Document Revision | 4 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |