myServer File Disclosure Variant Vulnerability
BID:8708
Info
myServer File Disclosure Variant Vulnerability
| Bugtraq ID: | 8708 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 24 2003 12:00AM |
| Updated: | Sep 24 2003 12:00AM |
| Credit: | Discovery is credited to scrap <[email protected]>. |
| Vulnerable: |
myServer myServer 0.4.3 |
| Not Vulnerable: |
myServer myServer 0.5 |
Discussion
myServer File Disclosure Variant Vulnerability
A file disclosure vulnerability has been reported in myServer that could permit remote attackers to gain access to sensitive files outside of the web root directory of the server. This is a variant of previously reported vulnerabilities (in particular BID 7944) that is known to affect myServer 0.4.3. The main difference is that it is possible to escape web root using a combination of './' and '../' sequences.
A file disclosure vulnerability has been reported in myServer that could permit remote attackers to gain access to sensitive files outside of the web root directory of the server. This is a variant of previously reported vulnerabilities (in particular BID 7944) that is known to affect myServer 0.4.3. The main difference is that it is possible to escape web root using a combination of './' and '../' sequences.
Exploit / POC
myServer File Disclosure Variant Vulnerability
This issue can be exploited with a web browser.
This issue can be exploited with a web browser.