PT-2003-2358 · Apple · Darwin Streaming Server
Joe Testa
·
Published
2003-12-31
·
Updated
2017-07-29
·
CVE-2003-1413
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Darwin Streaming Server version 4.1.1
Description
The issue allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the
filename parameter and comparing the resulting error messages. This is related to the parse xml.cgi component.Recommendations
For Darwin Streaming Server version 4.1.1, consider restricting access to the
parse xml.cgi component until a patch is available. As a temporary workaround, avoid using the filename parameter with ".." sequences in the affected API endpoint.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Darwin Streaming Server