Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Mollensoft Software Enceladus Server Suite Directory Traversal Vulnerability

It has been reported that Enceladus fails to properly sanitize web requests. By sending a malicious web request to the vulnerable server, using directory traversal sequences, it is possible for a remote attacker to view and download sensitive resources located outside of the web root.

An attacker is able to traverse outside of the established web root by using dot-dot-slash (../) directory traversal sequences. An attacker may be able to obtain any web server readable files from outside of the web root directory.







 

Privacy Statement
Copyright 2009, SecurityFocus