Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Avenger's News System Directory Traversal Vulnerability

Avenger's News System (ANS) is a simple form-based web site management tool written in Perl. It will run on most Unix and Linux variants.

ANS does not filter dot-dot-slash (../) sequences from web requests, making it prone to directory traversal attacks. As a result, the attacker may display the contents of arbitrary web-readable files.

Information disclosed in this manner may aid the attacker in further "intelligent" attacks against the host.







 

Privacy Statement
Copyright 2008, SecurityFocus