vendor:
Gnapster and Knapster
by:
no_maam and Dennis (conrad.d@web.de)
7.5
CVSS
HIGH
Design Error
20
CWE
Product Name: Gnapster and Knapster
Affected Version From: Gnapster prior to 1.3.9 and Knapster up to 0.10
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2000
Gnapster / Knapster “view any file” exploit
Due to a design error in Gnapster and Knapster it's possible to view any file Gnapster / Knapster has access to because the application fails to check that the requested file is an explicitly shared MP3 file before providing it.
Mitigation:
Upgrade to the latest version of Gnapster and Knapster.