The daemon for GeneWeb before 4.09 does not properly handle requested paths, which allows remote attackers to read arbitrary files via a crafted URL.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/6549 | vdb entry |
http://www.debian.org/security/2003/dsa-223 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11021 | vdb entry |
http://cristal.inria.fr/~ddr/GeneWeb/en/version/4.09.html |