vendor:
MegaBrowser
by:
James Bercegay
7.5
CVSS
HIGH
Directory Traversal and FTP User Enumeration
22, 200
CWE
Product Name: MegaBrowser
Affected Version From: 0.71b
Affected Version To: 0.71b
Patch Exists: NO
Related CWE: N/A
CPE: a:quality_programming_corporation:megabrowser
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2005
MegaBrowser Multiple Vulnerabilities
MegaBrowser HTTP server is vulnerable to a directory traversal vulnerability which allows access to any file on the system as well as directory viewing of the root web directory. While not as serious as the previously mentioned vuln, this still poses a threat as it may allow an attacker to harvest a list of valid FTP usernames on the system.
Mitigation:
Vendor contacted, but never replied. No known solution.