vendor:
WebServer
by:
SecurityFocus
7.5
CVSS
HIGH
Directory Management Policy Bypass
20
CWE
Product Name: WebServer
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
GoAhead WebServer Directory Management Policy Bypass Vulnerability
GoAhead WebServer is prone to a vulnerability that may permit remote attackers to bypass directory management policy. It is reported that certain syntax may be used in HTTP GET requests to bypass the policy for how certain request should be handled, for example, a script that should be interpreted may be downloaded by the attacker instead. This could allow for unauthorized access to resources hosted on the server, likely resulting in disclosure of sensitive information such as script source code.
Mitigation:
Ensure that directory management policies are properly configured and enforced.