vendor:
Aspen
by:
Daniel Ricardo dos Santos
4,3
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: Aspen
Affected Version From: 0.8
Affected Version To: 0.8
Patch Exists: YES
Related CWE: CVE-2013-2619
CPE: a:zetadev:aspen
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
Aspen 0.8 – Directory Traversal
Aspen 0.8 is vulnerable to a directory traversal when directory indexing is turned on (default configuration in this version) and a user requests, for instance localhost/../../../../../../../etc/passwd. The vulnerability may be tested with the following command-line: curl -v4 http://<server>:<port>/../../../../../../etc/passwd.
Mitigation:
Upgrade to version 0.22 - http://aspen.io/