vendor:
Femitter Server
by:
Anonymous
4,3
CVSS
MEDIUM
Source Disclosure and Directory Traversal
22
CWE
Product Name: Femitter Server
Affected Version From: v1.03
Affected Version To: v1.03
Patch Exists: No
Related CWE: N/A
CPE: a:acritum:femitter_server:1.03
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2
2020
Acritum Femitter Server v1.03 HTTP and FTP Server Vulnerabilities
Acritum Femitter Server v1.03 is a HTTP and FTP Server for Windows. Source Disclosure Vulnerability allows even some files like .html to be downloaded from this vulnerability by putting '.' in the end of the file. Directory Traversal Vulnerability allows access to the C Dir if the Femitter Server is installed in 'Program Files'. 403 Forbidden Error can be bypassed by adding hex and a '%<file.type>' in the end.
Mitigation:
Ensure that the Femitter Server is not installed in 'Program Files' and that the 'Combined Server' option is not selected.