vendor:
Voyager
by:
SecurityFocus
8.8
CVSS
HIGH
Path Traversal
22
CWE
Product Name: Voyager
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2001
Path Traversal
The web server supplied with the QNX Voyager demo disk contains a vulnerability in which it will follow relative paths passed to it in requests, including ../ style paths, which will allow Voyager to serve pages outside of the "document root". Additionally, the web server does not have sufficient security restrictions, allowing it to access any file, including protected files and special /dev entries. DoS attacks can be performed by requesting files under /.photon/ and recent PPP passwords can be exposed by requesting files under /etc/ppp/.
Mitigation:
Users should not use the Voyager web server in a production environment.