It has been reported that JWalk Server fails to properly sanitize web requests. By sending a malicious web request to the vulnerable server, using encoded directory traversal sequences, it is possible for a remote attacker to access sensitive resources located outside of the web root. Disclosure of sensitive system files may aid the attacker in launching further attacks against the target system.
It has been reported that JWalk Server fails to properly sanitize web requests. By sending a malicious web request to the vulnerable server, using encoded directory traversal sequences, it is possible for a remote attacker to access sensitive resources located outside of the web root. Disclosure of sensitive system files may aid the attacker in launching further attacks against the target system.