[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
www file share pro 5.30 insecure multiple
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: www file share pro 5.30 insecure multiple
- From: output@xxxxxxxx
- Date: 21 May 2008 20:27:44 -0000
this server that now has reached 5.30 per version still contains many elements
of insecurity:
does not control the file extensions loaded
not figure the pass not esitone setting permits 666 777 etc.
Min poc:
http://gmda.altervista.org/wfsp530xpl/wfsp530exp.bat.txt