vendor:
SD Server
by:
SecurityFocus
8,8
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: SD Server
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2004-0753
CPE: a:sd_server:sd_server
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unknown
2004
Directory Traversal Vulnerability in SD Server
SD Server is vulnerable to a directory traversal attack, which allows an attacker to gain access to potentially sensitive system files. This is possible due to the way SD Server handles certain types of requests. An example of such an attack is demonstrated in the URL provided, which attempts to access the SAM file in the Windows repair directory.
Mitigation:
Restrict access to the web server process and ensure that the web server process has the least privileges necessary.