|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
TelCondex's SimpleWebServer version 2.13.31027 Build 3289 contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker sends specially-crafted HTTP requests containing modified "dot dot dot" sequences that use three dots instead of two (.../) which will disclose files outside of the root directory information resulting in a loss of confidentiality.
|
|
Classification |
Attack Type:
Input Manipulation
|
|
Technical |
SimpleWebServer, developed by TelCondex Software, is a freely available Web server for Microsoft Windows platforms.
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
SimpleWebServer
 |
2.1.3 |
|
|
|
|
Tools & Filters |
|
Nikto
|
1488
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|