|
Avenger's News System Directory Traversal Vulnerability
Avenger's News System (ANS) is a simple form-based web site management tool written in Perl. It will run on most Unix and Linux variants. ANS does not filter dot-dot-slash (../) sequences from web requests, making it prone to directory traversal attacks. As a result, the attacker may display the contents of arbitrary web-readable files. Information disclosed in this manner may aid the attacker in further "intelligent" attacks against the host. |
|
|
Privacy Statement |