Junglewise Threat Intelligence

CVE-1999-1069: iCat Carbo Server directory traversal in carbo.dll

CVE-1999-1069 · Severity: medium · CVSS 5 · Published 1997-11-08

Executive brief

iCat Carbo Server is an early e-commerce application server. A security flaw in the server's carbo.dll component allows an unauthorized person to access and read sensitive files on the host computer. This could lead to the exposure of configuration files, system data, or other private information stored on the server.

Technical details

A directory traversal vulnerability exists in the carbo.dll component of iCat Carbo Server 3.0.0. The issue stems from insufficient sanitization of the 'icatcommand' parameter, which allows an unauthenticated remote attacker to use dot-dot-slash (../) sequences to escape the intended web directory. By crafting specific requests, an attacker can read arbitrary files on the filesystem with the privileges of the web server process. This is a classic path traversal flaw reachable over the network without prior authentication.

Affected products

  • iCat Carbo Server 3.0.0

Timeline

  • 1997-11-08: disclosed: Initial publication date

References