Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read files outside the web root, including the abyss.conf file, via URL-encoded .. (dot dot) sequences in the HTTP request.
Link | Tags |
---|---|
http://www.aprelium.com/forum/viewtopic.php?t=24 | patch |
http://www.iss.net/security_center/static/8805.php | vdb entry patch vendor advisory |
http://archives.neohapsis.com/archives/bugtraq/2002-04/0110.html | mailing list exploit patch vendor advisory |
http://www.securityfocus.com/bid/4466 | exploit vdb entry patch vendor advisory |