Bug: GNUMP3d Discloses Files on the Target System to Remote Users and Permits Cross-Site Scripting Attacks (WLB-2005100073 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: GNUMP3d Discloses Files on the Target System to Remote Users and Permits Cross-Site Scripting Attacks
 Credit: Steve Kemp
 Date: 2005.10.29
 CWE: N/A
 CVE: CVE-2005-3122 (Show details)
CVE-2005-3123 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Low
No
Yes

Debian reported:

Steve Kemp discovered two vulnerabilities in gnump3d, a streaming
server for MP3 and OGG files. The Common Vulnerabilities and
Exposures Project identifies the following problems:

CVE-2005-3122

The 404 error page does not strip malicious javascript content
from the resulting page, which would be executed in the victims
browser.

CVE-2005-3123

By using specially crafting URLs it is possible to read arbitary
files to which the user of the streaming server has access to.

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com