SimpleServer:WWW Hex Encoded URL...

- AV AC AU C I A
发布: 2001-07-26
修订: 2025-04-13

SimpleServer:WWW is a freely available HTTP daemon available from AnalogX. It is designed for simplicity of operation. A problem with the web server could allow a remote user to execute arbitrary commands, and potentially gain local access to the system. The problem is in the validation of URLs that have been encoded in hex. By encoding an URL in hex, it is possible to bypass any filtering for directory traversal, and execute arbitrary programs on the local system.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息