Quik-Serv Web Server Arbitrary File Disclosure Vulnerability
BID:4425
Info
Quik-Serv Web Server Arbitrary File Disclosure Vulnerability
| Bugtraq ID: | 4425 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0556 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 03 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Vulnerability discovery credited to a b <[email protected]> |
| Vulnerable: |
Deep Forest Software Quik-Serv Webserver 1.1 B |
| Not Vulnerable: | |
Discussion
Quik-Serv Web Server Arbitrary File Disclosure Vulnerability
Quik-Serv web server is a free web server for the Microsoft Windows platform. It is distributed and maintained by Deep Forest Software.
It is possible for a remote user to gain access to arbitrary files on a vulnerable system. The Quik-Serv web server does not properly handle requests containing dot-dot-slash (../) requests. This could make it possible for a remote user to view files accessible by the web server process.
Quik-Serv web server is a free web server for the Microsoft Windows platform. It is distributed and maintained by Deep Forest Software.
It is possible for a remote user to gain access to arbitrary files on a vulnerable system. The Quik-Serv web server does not properly handle requests containing dot-dot-slash (../) requests. This could make it possible for a remote user to view files accessible by the web server process.
Exploit / POC
Quik-Serv Web Server Arbitrary File Disclosure Vulnerability
This vulnerability may be exploited with a web browser.
This vulnerability may be exploited with a web browser.