Visit our newest sister site!
Hundreds of free aircraft flight manuals
Civilian • Historical • Military • Declassified • FREE!


TUCoPS :: Web :: Servers :: jana3~1.htm

Jana Webserver v1.45, 1.46, 2.0Beta1 hex-encoded dot-dot directory traversal



Vulnerability

    Jana

Affected

    Jana Webserver v1.45, 1.46, 2.0Beta1

Description

    Following is the contin. of previous "Jana chapter" available at:

        http://oliver.efri.hr/~crv/security/bugs/Others/jana2.html

    This input was made  by nemesystm of the  DHC.  Jana Webserver  is
    well, a webserver.  It has a hex-encoded dot dot bug and a  denial
    of service.

    Tested to be vulnerable to the hex-encoded dot dot bug are:
    - Jana Webserver v1.45
    - Jana Webserver v1.46

    All older versions are assumed to be vulnerable as well.

    Tested to be vulnerable to the denial of service are:
    - Jana Webserver v1.45
    - Jana Webserver v1.46
    - Jana Webserver v2.0 Beta 1

    All older versions are assumed to be vulnerable as well.

    To test this vulnerability, try the following:

        www.server.com/%2e%2e/%2e%2e/%2e%2e/scandisk.log

    Add  or  remove  %2e%2e/'s  to  reflect  the  directory  Jana  was
    installed in.  The denial of service can be tested by requesting

        www.server.com/aux

Solution

    This is fixed in the next release of Jana.


TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH