Executive brief
A security vulnerability exists in the SGI Performer API Search Tool, a utility used for searching technical documentation. An attacker can exploit this flaw to remotely access and read sensitive files stored on the server that should not be publicly accessible. This could lead to the exposure of system configuration details or other private data, potentially aiding further attacks against the organization's infrastructure.
Technical details
The vulnerability is a classic directory traversal flaw located in the 'pfdisplay.cgi' (also known as 'pfdispaly.cgi') script, which is part of the SGI Performer API Search Tool (performer_tools). The CGI script fails to properly sanitize user-supplied input used in file path construction. A remote, unauthenticated attacker can use special characters (such as '../') in a URL request to bypass intended directory restrictions. This allows the attacker to read any file on the server that the web server process has permissions to access. SGI released a security advisory and patches in April 1998 to address this issue.
Affected products
- SGI Performer API Search Tool (performer_tools) All versions prior to April 1998
Timeline
- 1998-04-01: advisory: SGI released security advisory 19980401-01-P
- 1998-04-03: disclosed: Vulnerability published in NVD