[<prev] [next>] [day] [month] [year] [list]
Message-Id: <20070211232550.ABD7120D787@mrelay2.st2.lyceu.net>
Date: Mon, 12 Feb 2007 00:25:49 +0100
From: Daniel Nyström <daniel.nystrom@...ed.net>
To: <bugtraq@...urityfocus.com>
Subject: Miniwebsvr 0.0.6 - Directory traversal
Hello!
Miniwebsvr 0.0.6 suffers from a directory traversal flaw.
"Exploit" :
http://yoursite/..%00
Attack vector seems limited as you're only able to list one level down.
Cheers,
Daniel Nyström, daniel.nystrom@...ed.net
Fredrik Wessberg, fredd3@...mail.com
Powered by blists - more mailing lists