Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory contents via a trailing null character.
Link | Tags |
---|---|
http://www.osvdb.org/20076 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/22785 | vdb entry |
http://www.osvdb.org/20075 | vdb entry |
http://www.securityfocus.com/bid/15135 | exploit vdb entry patch |
http://securitytracker.com/id?1015079 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/22786 | vdb entry |
http://secunia.com/advisories/17243 | exploit third party advisory patch vendor advisory |