Vulnerability description
It is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
This vulnerability affects /.
The impact of this vulnerability
An attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
Attack details
The Cookie variable Y2User-94564=111-222-1933email@address.com; has been set to .
View HTTP headers
Request
GET / HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host:
www.pnvd.nlCookie: Y2User-94564=111-222-1933email@address.com;;Y2Pass-94564=111-222-1933email@address.com;Y2Sess-94564=111-222-1933email@address.com
Connection: Close
Pragma: no-cacheResponse
HTTP/1.1 200 OK
Date: Sun, 01 Oct 2006 17:44:42 GMT
Server: Apache/2.0.55 (Debian) mod_python/3.1.3 Python/2.3.5 PHP/4.4.2-1.1 mod_perl/2.0.2 Perl/v5.8.8
Last-Modified: Sun, 03 Sep 2006 23:41:04 GMT
ETag: "51401b-384-289e2400"
Accept-Ranges: bytes
Content-Length: 900
Connection: close
Content-Type: text/html; charset=ISO-8859-1 View HTML response
Launch the attack with HTTP Editor
How to fix this vulnerability
Analyse the source code of this script and solve the problem.
Voila .... :0 niet verwacht dat het zo snel ging...
Ze hebben de apache server eindelijk geupdate nu maar hopen dat
ze dat bug gaan fixen, voordat het weer te laat is.