Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files via a URL that contains a "....", a variant of the dot dot directory traversal attack.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2000-07/0426.html | mailing list vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/5021 | vdb entry |
http://www.securityfocus.com/bid/1522 | vdb entry vendor advisory |