Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:INFO-LEAK:GOAHEAD-PERM

Severity

Warning

Recommended

No

Category

HTTP

Keywords

GoAhead WebServer Directory Permissions Bypass

Release Date

2004/09/15

Update Number

1213

Supported Platforms

di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: GoAhead WebServer Directory Permissions Bypass


This signature detects attempts to bypass directory permissions set on the /cgi-bin directory of a GoAhead Web server. GoAhead Web Server versions 2.1.8 and earlier are vulnerable. Attackers can supply an invalid URL to the server to reveal the contents of certain private directories on the server.

Extended Description

GoAhead WebServer is prone to a vulnerability that may permit remote attackers to bypass directory management policy. It is reported that certain syntax may be used in HTTP GET requests to bypass the policy for how certain request should be handled, for example, a script that should be interpreted may be downloaded by the attacker instead. This could allow for unauthorized access to resources hosted on the server, likely resulting in disclosure of sensitive information such as script source code. The exact consequences will depend on what sort of directory management policy is in place and also the nature of information included in scripts or other sensitive resources hosted on the server.

Affected Products

  • Goahead_software goahead_webserver 2.0.0
  • Goahead_software goahead_webserver 2.1.0
  • Goahead_software goahead_webserver 2.1.1
  • Goahead_software goahead_webserver 2.1.2
  • Goahead_software goahead_webserver 2.1.3
  • Goahead_software goahead_webserver 2.1.4
  • Goahead_software goahead_webserver 2.1.5
  • Goahead_software goahead_webserver 2.1.6
  • Goahead_software goahead_webserver 2.1.7
  • Goahead_software goahead_webserver 2.1.8

References

  • BugTraq: 9450
  • CVE: CVE-2001-0228
  • URL: http://archives.neohapsis.com/archives/bugtraq/2001-02/0022.html
  • URL: http://www.securityfocus.com/archive/1/350231

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out