vendor:
Yaws
by:
nitr0us (Alejandro Hernandez H.)
5.5
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: Yaws
Affected Version From: 1.89
Affected Version To: 1.89
Patch Exists: NO
Related CWE:
CPE: a:yaws:yaws:1.89
Platforms Tested: Windows XP Service Pack 2
2010
Yaws 1.89 Directory Traversal
This exploit allows an attacker to traverse directories and access files outside of the intended directory structure. The exploit is performed using the DotDotPwn tool with specific parameters.
Mitigation:
The vulnerability can be mitigated by implementing proper input validation and sanitization to prevent directory traversal attacks.