vendor:
Abyss Web Server
by:
SecurityFocus
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Abyss Web Server
Affected Version From: 1
Affected Version To: 1.2
Patch Exists: YES
Related CWE: N/A
CPE: a:aprelium:abyss_web_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2002
Authentication Bypass Vulnerability in Abyss Web Server
It has been reported that Abyss Web Server is prone to an authentication bypass vulnerability that may allow an attacker to gain access to server resources. This issue may be carried out by accessing a password protected directory under which the server is running by adding a period as '.' or '%2e' at the end of a URL request. This problem only presents itself when the server is installed on a Linux system running FAT32.
Mitigation:
Upgrade to Abyss Web Server version 1.2 or later.