MyWebServer 1.0.3 allows remote attackers to bypass authentication, modify configuration, and read arbitrary files via a direct HTTP request to (1) /admin or (2) ServerProperties.html.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/11254 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17520 | vdb entry |
http://securitytracker.com/id?1011461 | vdb entry |
http://marc.info/?l=bugtraq&m=109630333230707&w=2 | mailing list |