vendor:
SimpleServer:WWW
by:
THRAN
7.5
CVSS
HIGH
Command Execution
78
CWE
Product Name: SimpleServer:WWW
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:analogx:simpleserver:www
Platforms Tested:
2001
SimpleServer:WWW Command Execution Vulnerability
A problem with the web server could allow a remote user to execute arbitrary commands, and potentially gain local access to the system. The problem is in the validation of URLs that have been encoded in hex. By encoding an URL in hex, it is possible to bypass any filtering for directory traversal, and execute arbitrary programs on the local system.
Mitigation:
Apply the latest patch or upgrade to a newer version of SimpleServer:WWW.