vendor:
Zervit
by:
e.wiZz!
7,5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Zervit
Affected Version From: 0.2.1
Affected Version To: 0.2.1
Patch Exists: YES
Related CWE: CVE-2009-1445
CPE: a:zervit:zervit:0.2.1
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Zervit Webserver Directory Traversal
Zervit Webserver is vulnerable to a directory traversal attack. This vulnerability allows an attacker to view arbitrary files on the server, including sensitive files such as boot.ini. The vulnerability is caused due to the improper sanitization of user-supplied input to the 'GET' parameter. This can be exploited to read arbitrary files on the server by sending a specially crafted HTTP request.
Mitigation:
Upgrade to the latest version of Zervit Webserver.