Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files via (1) multi-dot "......" sequences, or (2) "%5c%2e%2e" (encoded "\..") sequences, in the URL.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/9486 | vdb entry exploit |
http://securitytracker.com/id?1008840 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/14948 | vdb entry |
http://marc.info/?l=bugtraq&m=107497413413907&w=2 | mailing list |