Nessus Plugin #15749

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

Anaconda Double NULL Encoded Remote File Retrieval

Family:
Remote file access
Category:
infos
Copyright:
This script is Copyright (C) 2004 Noam Rathaus
Summary:
Anaconda Foundation Directory Double NULL Encoded Remote File Retrieval
Version:
$Revision: 1.1 $
Cve_id:
-
Bugtraq_id:
-
Xrefs:
-
Description:

The remote Anaconda Foundation Directory contains a flaw
that allows anyone to read arbitrary files with root (super-user)
privileges, by embedding a double null byte in a URL, as in :

http://www.example.com/cgi-bin/apexec.pl?etype=odp&template=../../../../../../..../../etc/passwd%%0000.html&passurl=/category/

Solution : Contact your vendor for updated software.
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.