Oh no! Some styles failed to load. 😵 Please try reloading this page
Menu â–¾ â–´

#14 edit.cgi can read any file of the system

0.4.x
closed
General (39)
9
2012-09-14
2004-01-02
No

I'm using webmin 2.121 with the last devel version of
your module...
If I use the URL:

https://mywebminserver:10000/dansguardian/edit.cgi?file=[FILE]

I can edit any file of my system, like:

https://mywebminserver:10000/dansguardian/edit.cgi?file=/etc/shadow

Is there a way to avoid this and jail my dansguardian
webmin module in /etc/dansguardian ?

Thank you very much and congradulations for your work!

Sorry if this was noticed before...

Discussion

  • Adam Kennedy

    Adam Kennedy - 2004-01-03

    Logged In: YES
    user_id=49552

    That is definately not good. I will modify edit.cgi and
    verify that all other files are locked to their appropriate
    directories. I will release a new version hopefully within a
    week.

     
  • Adam Kennedy

    Adam Kennedy - 2004-01-07

    Logged In: YES
    user_id=49552

    Fixed in CVS. Fixed file is also attached. Version 0.5.9
    will be released later this week with fix included. Thanks
    for finding this!

     
  • Adam Kennedy

    Adam Kennedy - 2004-01-07
     

Log in to post a comment.

Get latest updates about Open Source Projects, Conferences and News.

Sign Up No, Thank you