Junglewise Threat Intelligence

CVE-1999-1250: Blue World Lasso arbitrary file read via CGI program

CVE-1999-1250 · Severity: medium · CVSS 5 · Published 1997-08-19

Executive brief

A vulnerability in the Lasso CGI application, commonly used with WebSTAR web servers, allows unauthorized individuals to view sensitive files on the server. By sending a specially crafted request, a remote attacker can bypass security restrictions to read arbitrary documents and configuration files. This could lead to the exposure of private data, credentials, or system information, potentially facilitating further attacks on the organization's infrastructure.

Technical details

The Lasso CGI application contains an information disclosure vulnerability that allows for arbitrary file disclosure. A remote, unauthenticated attacker can exploit this by sending a crafted HTTP request to the Lasso CGI program. The root cause is insufficient validation of file paths or parameters within the CGI script, enabling the retrieval of files outside of the intended web directory. This vulnerability was identified in 1997 and affects Lasso deployments on WebSTAR and similar web server environments. Users should ensure they are using patched versions of the Lasso middleware.

Affected products

  • Blue World Lasso All versions prior to August 1997
  • StarNine Technologies WebSTAR

Timeline

  • 1997-08-19: disclosed: Initial public disclosure of the vulnerability.
  • 1997-08-19: advisory: NVD published date.

References