Falcon web server 2.0.0.1020 and earlier allows remote attackers to bypass authentication and read restricted files via an extra / (slash) in the requested URL.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=101363946626951&w=2 | mailing list |
http://marc.info/?l=bugtraq&m=102253858809370&w=2 | mailing list |
http://www.securityfocus.com/bid/4099 | vdb entry |
http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0082.html | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/8189 | vdb entry |