vendor:
Momentum Series Web Server
by:
Numan Türle
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Momentum Series Web Server
Affected Version From: Bullwark Momentum Series Web Server JAWS/1.0
Affected Version To: Bullwark Momentum Series Web Server JAWS/1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:bullwark:momentum_series_web_server:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
Bullwark Momentum Series JAWS 1.0 – Directory Traversal
A directory traversal vulnerability exists in Bullwark Momentum Series Web Server JAWS/1.0. An attacker can send a specially crafted HTTP request containing '../' sequences to read arbitrary files from the server.
Mitigation:
Ensure that user input is validated and filtered before being used in file system operations.