Uploaded image for project: 'Cocoon'
  1. Cocoon
  2. COCOON-848

Security : Directory traversal in "view-source"

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Critical
    • Resolution: Fixed
    • 2.1.2
    • None
    • - Components: Avalon
    • None
    • Operating System: All
      Platform: All
    • 23949

    Description

      http://a_Host.com:8888/samples/view-source?filename=../../../boot.ini allows
      to download the "boot.ini" file (located in the root of C drive under Window
      NT/2000/XP).

      I know this is only a sample script but unfortunately a lot of people do
      install their production machines with samples installed...

      A check on the filename should be done.

      Attachments

        Activity

          People

            Unassigned Unassigned
            thierry.deleeuw@advalvas.be Thierry De Leeuw
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: