|
|
|
![]() |
Vulnerability Note VU#132099Jana Server does not adequately validate user input thereby allowing directory traversalOverviewJana Server contains a directory traversal vulnerability.I. DescriptionVersions 1.4x of Jana Server, a web server for Windows developed by T. Hauck, do not properly filter requests for hexadecimal encodings of ".." (dot-dot) and allows directory traversal out of the HTTP document root directory.II. ImpactRemote users can view any file on the server with the privileges of the Jana server process.III. SolutionUpgrade to Jana Server 2.0 beta or later at:http://www.jana-server.ocm.de/en/index.htm?/en/download.htm
References
Thanks to nemesystm of the DHC for discovering this vulnerability. This document was written by Shawn Van Ittersum.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||