vendor:
Xnews
by:
r0ut3r
5.5
CVSS
MEDIUM
Remote File Disclosure
200
CWE
Product Name: Xnews
Affected Version From: 1.0.1
Affected Version To: 1.0.1
Patch Exists: NO
Related CWE:
CPE: xpression.hogsmeade-village.com
Platforms Tested:
2007
XNews Remote File Disclosure Exploit
This exploit allows an attacker to remotely disclose files on a system running Xnews 1.0.1. The vulnerability was discovered by r0ut3r and can be exploited by sending a specially crafted request to the server. The exploit has been tested on Xnews 1.0.1.
Mitigation:
To mitigate this vulnerability, it is recommended to upgrade to a newer version of Xnews that includes a patch for this issue.