Bugtraq mailing list archives

Enceladus Server Suite traversal directory vulnerability


From: "luca.ercoli () inwind it" <luca.ercoli () inwind it>
Date: Sun, 8 Dec 2002 20:15:51 +0100

Summary: Enceladus Server Suite is an internet/intranet lightweight web
and ftp server for windows.

Details: The web server has been found to contain a security flaw that
allows attackers to travers up the root directory and view/download
files on the system.

Vulnerable System: Enceladus Server Suite version 2.6.1

Example: http://host/../

From Luca Ercoli luca.ercoli () inwind it


Current thread: