Ashley Brown iWeb Server Directory...

- AV AC AU C I A
发布: 2003-04-15
修订: 2025-04-13

iWeb Server does not perform correct access validation on client requested paths which include "../" character sequences. It is possible for attackers to obtain files and directories outside of the webroot by requesting their path relative to the current directory. This may be exploited by a remote attacker to potentially disclose sensitive information. The author has issued a new version that is not vulnerable to this attack.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息