MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions, which allows remote attackers to obtain sensitive information (script source code) via a modified extension, as demonstrated by post.mscgI.
The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.
Link | Tags |
---|---|
http://osvdb.org/37505 | vdb entry broken link |
http://secunia.com/advisories/25754 | broken link third party advisory vendor advisory |
http://securityreason.com/securityalert/2827 | third party advisory |
http://www.securityfocus.com/archive/1/471914/100/0/threaded | mailing list vdb entry third party advisory broken link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34977 | vdb entry third party advisory |
http://www.securityfocus.com/bid/24571 | vdb entry third party advisory broken link |