Home page logo

bugtraq logo Bugtraq mailing list archives

MyServer-0.8.9 - source code disclosure
From: imprili () gmail com
Date: 21 Jun 2007 00:45:05 -0000

The vulnerability is caused due to a parser error of the filename extension supplied by the user in the URL.
This can be exploited to retrieve the source code of script files.
Found By:Shay Priel aka Prili

http://localhost/cgi-bin/post.mscgI   (I - capital letter)

  By Date           By Thread  

Current thread:
  • MyServer-0.8.9 - source code disclosure imprili (Jun 21)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]