[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
MyServer-0.8.9 - source code disclosure
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: MyServer-0.8.9 - source code disclosure
- From: imprili@xxxxxxxxx
- Date: 21 Jun 2007 00:45:05 -0000
The vulnerability is caused due to a parser error of the filename extension
supplied by the user in the URL.
This can be exploited to retrieve the source code of script files.
Found By:Shay Priel aka Prili
site:
http://www.myserverproject.net/
poc:
----
http://localhost/cgi-bin/post.mscgI (I - capital letter)