BearShare File Disclosure Variant...

- AV AC AU C I A
发布: 2002-10-04
修订: 2025-04-13

BearShare can be run in Website mode, which allows users to host files via a webserver which is bundled in the product. The BearShare webserver is prone to directory traversal attacks. This may allow remote attackers to break out of the web root directory and browse the filesystem of the host running the software. This issue is a variant of the vulnerability described in Bugtraq ID 2672. The variant issue was unsuccessfully addressed in version 4.0.6. It is still possible to disclose files with a malicious URL encoded request to the webserver.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息