CERT home
vulnerabilities & fixesevaluations & practicesresearch & analysistraining & education
homesearchFAQsite indexcontact
Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information
 

 View Notes By
Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric

Vulnerability Note VU#651994

SEDUM HTTP server permits directory traversal

Overview

The SEDUM web server permits intruders to access files outside the web root.

I. Description

The SEDUM Web Server permits intruders to access files outside the web root using a GET request containing ".." (dot dot). This can expose files (including files with sensitive information) to exposure by unauthorized individuals.

II. Impact

Intruders can read files accessible to the SEDUM web server they should not be able to read .

III. Solution

The CERT/CC is currently unaware of a practical solution to this problem.

Systems Affected

No Information Available

References


http://www.securityfocus.com/bid/2335
http://xforce.iss.net/static/6063.php
http://www.securityfocus.com/archive/1/160452

Credit

Our thanks to Joe Testa, who originally reported this problem on BugTraq.

This document was written by Shawn V. Hernan.

Other Information

Date Public02/04/2001
Date First Published05/15/2001 11:15:32 PM
Date Last Updated06/25/2001
CERT Advisory 
CVE NameCAN-2001-0199
Metric1.50
Document Revision5

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

Copyright 2001 Carnegie Mellon University