header-logo
Suggest Exploit
vendor:
URL Live! free webserver
by:
Unknown
5.5
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: URL Live! free webserver
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Not specified
CPE: a:pacific_software:url_live!_free_webserver
Metasploit:
Other Scripts:
Platforms Tested: Unknown
Unknown

Directory Traversal Vulnerability in URL Live! free webserver from Pacific software

The URL Live! free webserver from Pacific software is susceptible to the "../" directory traversal vulnerability. By using the '../' string in a URL, an attacker can gain read access to files outside the intended web file structure.

Mitigation:

Upgrade to a patched version or apply appropriate security measures to prevent directory traversal attacks.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/746/info

The URL Live! free webserver from Pacific software is susceptible to the "../" directory traversal vulnerability. By using the '../' string in a URL, an attacker can gain read access to files outside the intended web file structure. 

Example:
http ://xyz.com/../../../config.sys