Nessus Plugin #10574

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

PHPix directory traversal vulnerability

Family:
CGI abuses
Category:
infos
Copyright:
This script is Copyright (C) 2000 Zorgon <zorgon@linuxstart.com>
Summary:
PHPix directory traversal vulnerability
Version:
$Revision: 1.12 $
Cve_id:
CVE-2000-0919
Bugtraq_id:
1773
Xrefs:
-
Description:
PHPix program allows an attacker to read arbitrary files on the remote web server, prefixing the pathname of the file with ..%2F..%2F..

Example:
GET /Album/?mode=album&album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&dispsize=640&start=0

will return all the files that are nested within /etc directory.

Solution: Contact your vendor for the latest software release.

Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.