SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information

Report a Vulnerability

 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#146704

Hyperseek 2000 hsx.cgi does not adequately filter user input disclosing directory listings and file contents

Overview

iWeb Systems Hyperseek search engine may allow malformed URL requests to access files outside the document root of a vulnerable system.

I. Description

A specially crafted URL can disclose the directory listing and files of the target system with read permissions.

II. Impact

Remote attackers may be able to disclose directory listings and files of the target system with read permissions.

III. Solution

Contact the vendor to obtain a patch.

Systems Affected

VendorStatusDate NotifiedDate Updated
IWeb SystemsVulnerable14-Feb-2003

References

http://www.securityfocus.com/bid/2314
http://www.hyperseek.com/hyperseek/

Credit

Mc GaN <vipersv@mail.ru>, has been publicly credited for discovering this vulnerability.

This document was written by Ian A. Finlay.

Other Information

Date Public:2001-01-28
Date First Published:2003-02-14
Date Last Updated:2003-02-14
CERT Advisory: 
CVE-ID(s):CAN-2001-0253
NVD-ID(s):CAN-2001-0253
US-CERT Technical Alerts: 
Severity Metric:4.50
Document Revision:18

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2003 Carnegie Mellon University
Disclaimers and copyright information
Get a PDF Reader