vendor:
FileUp(TM)
by:
Inge Henriksen
7,5
CVSS
HIGH
Script source disclosure
Not available
CWE
Product Name: FileUp(TM)
Affected Version From: SoftArtisans SAFileUp(TM) 5.0.14 (Standard)
Affected Version To: SoftArtisans SAFileUp(TM) 5.0.14 (Standard)
Patch Exists: Not available
Related CWE: Not available
CPE: Not available
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Web browser
2006
SoftArtisans FileUp viewsrc.asp remote script source disclosure exploit
SoftArtisans FileUp(TM) is a popular web server component for transactional uploading of files to a web server using a web browser. When installing SoftArtisans FileUp(TM) you should avoid installing the samples as viewsrc.asp can let remote anonymous users see script source code or configuration settings outside the /SAFileUpSamples virtual directory. This is accomplished by modifying the 'path' query variable to point to files outside the designated directory. A web browser from a remote location is a sufficient tool to see the source code or configuration settings in plain text.
Mitigation:
Avoid installing the samples of SoftArtisans FileUp(TM)