SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information

Report a Vulnerability

 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#124059

GoAhead WebServer information disclosure and authentication bypass vulnerabilities

Overview

GoAhead WebServer contains vulnerabilities that may allow an attacker to view source files containing sensitive information or bypass authentication. The information disclosure vulnerability was previously published as VU#975041.

I. Description

GoAhead WebServer contains vulnerabilities handling file requests. By sending the web server a specially crafted URL, an attacker may be able to view the source files containing sensitive information or bypass authentication. GoAhead WebServer has a history of source file disclosure vulnerabilities.

II. Impact

An attacker may be able to view any file on the web server, including files that contain sensitive information like usernames and passwords. An attacker may also be able to bypass authentication for protected files.

III. Solution

Release notes for GoAhead WebServer 2.1.8 indicate that these vulnerabilities have been addressed. GoAhead WebServer is not being actively maintained. Vendors who redistribute GoAhead WebServer or include it in other products may release updates to address these vulnerabilities. Vendors who have modified GoAhead WebServer may or may not be affected. See the Systems Affected section below for more information.

GoAhead WebServer 2.1.8 on the Microsoft Windows platform remains vulnerable to source file disclosure.

Restrict access

To reduce exposure to these vulnerabilities, restrict network access to vulnerable systems.

Systems Affected

VendorStatusDate NotifiedDate Updated
GoAhead Software, Inc.Affected2010-06-22
Rockwell AutomationVulnerable2009-12-29

References

http://www.ab.com/networks/architectures.html
http://data.goahead.com/Software/Webserver/2.1.8/release.htm#bug-with-urls-like-asp
http://data.goahead.com/Software/Webserver/2.1.8/release.htm#security-features-can-be-bypassed-by-adding-an-extra-slash-in-the-url-bug01518
http://www.kb.cert.org/vuls/id/975041
http://www.nerc.com/fileUploads/File/Events%20Analysis/A-2009-02-13-01.pdf
http://rockwellautomation.custhelp.com/app/answers/detail/a_id/57729
http://aluigi.altervista.org/adv/goahead-adv3.txt
http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=goahead+web+server
http://www.exploit-db.com/exploits/12815/

Credit

Thanks to Daniel Peck of Digital Bond, Inc. for reporting this issue.

This document was written by Ryan Giobbi.

Other Information

Date Public:2002-12-17
Date First Published:2009-02-05
Date Last Updated:2010-06-22
CERT Advisory: 
CVE-ID(s):CVE-2002-1603
NVD-ID(s):CVE-2002-1603
US-CERT Technical Alerts: 
Severity Metric:0.06
Document Revision:81

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2009 by US-CERT, a government organization
Disclaimers and copyright information
Get a PDF Reader