Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities Feb 28 2003 07:21PM
Joe Testa (Joe_Testa rapid7 com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Word.

I've found two other issues in QuickTime Streaming Server v4.1.1 that
seem to be fixed in the newest v4.1.3:

1.) File probing:

Request: http://localhost:1220/parse_xml.cgi?filename=../nonexistent
Response: 'Can't access HTML file '../...

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus