---------------------------------------------------------------------- 2003: 2,700 advisories published 2004: 3,100 advisories published 2005: 4,600 advisories published 2006: 5,300 advisories published How do you know which Secunia advisories are important to you? The Secunia Vulnerability Intelligence Solutions allows you to filter and structure all the information you need, so you can address issues effectively. Get a free trial of the Secunia Vulnerability Intelligence Solutions: http://corporate.secunia.com/how_to_buy/38/vi/?ref=secadv ---------------------------------------------------------------------- TITLE: Easy File Sharing Web Server Multiple Vulnerabilities SECUNIA ADVISORY ID: SA28007 VERIFY ADVISORY: http://secunia.com/advisories/28007/ CRITICAL: Moderately critical IMPACT: Exposure of sensitive information, System access WHERE: >From remote SOFTWARE: Easy File Sharing Web Server 4.x http://secunia.com/product/12461/ DESCRIPTION: Luigi Auriemma has reported some vulnerabilities in Easy File Sharing Web Server, which can be exploited by malicious people to disclose sensitive information and by malicious users to compromise a vulnerable system. 1) Input passed to unspecified parameters is not properly sanitised when uploading files. This can be exploited to upload files to arbitrary parent directories via directory traversal attacks. 2) An error exists when processing file download requests. This can be exploited to download any ".sdb" database file except "admin.sdb" or "user.sdb". 3) An error exists when processing username registration requests. This can be exploited to disclose the contents of arbitrary files in the users folder by creating an account with the username equal to the name of the file. The vulnerabilities are reported in version 4.5. Other versions may also be affected. SOLUTION: Restrict access to trusted users only. The vendor will reportedly fix the vulnerabilities in a future version. PROVIDED AND/OR DISCOVERED BY: Luigi Auriemma ORIGINAL ADVISORY: http://aluigi.altervista.org/adv/efsup-adv.txt ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------