Abyss Web Server HTTP GET Request Directory Contents Disclosure Vulnerability

A vulnerability has been reported for Abyss Web Server 1.0.3 running on a Microsoft Windows platform. It is possible for an attacker to make a request such that the contents of the web server root directory are revealed.

The vulnerability occurs due to the manner in which excessive '/' characters are handled in web requests. When a malformed GET command is received by Abyss Web Server, it will return an error page containing the directory listing of the specified directory.


 

Privacy Statement
Copyright 2010, SecurityFocus