[18998] in bugtraq
Vulnerability in Free Java Web Server
daemon@ATHENA.MIT.EDU (joetesta@HUSHMAIL.COM)
Sun Feb 4 23:56:45 2001
Content-type: multipart/mixed;
boundary="Hushpart_boundary_OvDyMuKPhlCNuYoNcOtSZQNAmccPDlNG"
Mime-version: 1.0
Message-ID: <200102041620.IAA19849@user7.hushmail.com>
Date: Sun, 4 Feb 2001 11:23:19 -0800
Reply-To: joetesta@HUSHMAIL.COM
From: joetesta@HUSHMAIL.COM
To: BUGTRAQ@SECURITYFOCUS.COM
--Hushpart_boundary_OvDyMuKPhlCNuYoNcOtSZQNAmccPDlNG
Content-type: text/plain
Vulnerability in Free Java Web Server
Overview
Free Java Web Server v1.0 is a Java web server available from
http://www.download.com. A vulnerability exists which allows a remote
user to break out of the web root using relative paths (ie: '..', '...').
Details
http://localhost/../[file outside web root]
http://localhost/.../[file outside web root]
Solution
No quick fix is possible.
Vendor Status
The author, Dattaraj J. Rao, was contacted via
<jagrao@goa1.dot.net.in> on Sunday, January 28, 2001. No reply was
received.
- Joe Testa ( joetesta@hushmail.com )
--Hushpart_boundary_OvDyMuKPhlCNuYoNcOtSZQNAmccPDlNG--
IMPORTANT NOTICE: If you are not using HushMail, this message could have been read easily by the many people who have access to your open personal email messages.
Get your FREE, totally secure email address at http://www.hushmail.com.