header-logo
Suggest Exploit
vendor:
MyServer
by:
Unknown
7.5
CVSS
HIGH
Remote Directory Traversal
22
CWE
Product Name: MyServer
Affected Version From: 0.7
Affected Version To: Unknown (other versions may also be vulnerable)
Patch Exists: NO
Related CWE:
CPE: a:myserver_project:myserver:0.7
Metasploit:
Other Scripts:
Platforms Tested: Unknown
Unknown

Remote Directory Traversal Vulnerability in MyServer

MyServer is prone to a remote directory traversal vulnerability. This issue occurs due to insufficient sanitization of user-supplied data, allowing improper access to potentially sensitive files located outside of the web server's document root.

Mitigation:

It is recommended to update to the latest version of MyServer to mitigate this vulnerability.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/11189/info

MyServer is reported prone to a remote directory traversal vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data. This vulnerability results in improper access to potentially sensitive files located outside of the document root of the web server. 

MyServer version 0.7 is reportedly affected by this issue, however, other versions may be vulnerable as well.

"GET ././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../"