Vulnerabilities > CVE-2000-0412 - Unspecified vulnerability in Napster Knapster Napster
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | John Donoghue Knapster 0.9/1.3.8 File Access Vulnerability. CVE-2000-0412. Remote exploit for unix platform |
id | EDB-ID:19905 |
last seen | 2016-02-02 |
modified | 2000-05-13 |
published | 2000-05-13 |
reporter | no_maam |
source | https://www.exploit-db.com/download/19905/ |
title | John Donoghue Knapster 0.9/1.3.8 File Access Vulnerability |
Nessus
NASL family | Peer-To-Peer File Sharing |
NASL id | GNAPSTER_GET_FILE.NASL |
description | An insecure Napster clone (e.g. Gnapster or Knapster) is running on the remote computer, which allows an intruder to read arbitrary files on this system, regardless of the shared status of the files. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 10408 |
published | 2000-05-12 |
reporter | This script is Copyright (C) 2000-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/10408 |
title | Gnapster Absolute Path Name Request Arbitrary File Access |
code |
|
References
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:18-gnapster.adv
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:18-gnapster.adv
- http://archives.neohapsis.com/archives/bugtraq/2000-05/0124.html
- http://archives.neohapsis.com/archives/bugtraq/2000-05/0124.html
- http://archives.neohapsis.com/archives/bugtraq/2000-05/0127.html
- http://archives.neohapsis.com/archives/bugtraq/2000-05/0127.html
- http://www.securityfocus.com/bid/1186
- http://www.securityfocus.com/bid/1186