OSVDB ID: 17460

Title: Whois.Cart language Variable Traversal Arbitrary File Access

Info

Disclosure

Jun 22, 2005

Discovery

Jun 21, 2005

Dates

Exploit

Jun 22, 2005

Solution

Unknown

Description

Whois.Cart has been reported to contain a flaw that allows the retrieval of arbitrary files via a traversal attack. Subsequent testing of this software has determined the original report was incorrect, and this vulnerability does not exist.

Classification

Location: Remote/Network Access Required
Attack Type: Information Disclosure, Input Manipulation
Impact: Loss of Confidentiality
Exploit: Exploit Available
OSVDB: Myth/Fake

Solution

The vulnerability reported is incorrect. No solution required.

Products

whoiscart.net

Whois.Cart

2.2

References

Credit

  • Elzar Stuffenbach - sanisoftBrand New Doo Doolinuxmail.org -


Direct URL: http://osvdb.org/36218