Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Abyss Web Server HTTP GET Request Directory Contents Disclosure Vulnerability

A vulnerability has been reported for Abyss Web Server 1.0.3 running on a Microsoft Windows platform. It is possible for an attacker to make a request such that the contents of the web server root directory are revealed.

The vulnerability occurs due to the manner in which excessive '/' characters are handled in web requests. When a malformed GET command is received by Abyss Web Server, it will return an error page containing the directory listing of the specified directory.







 

Privacy Statement
Copyright 2008, SecurityFocus