Description
The Administration console for Abyss Web Server 1.0.3 allows remote attackers to read files without providing login credentials via an HTTP request to a target file that ends in a "+" character.
Affected products
- aprelium_technologies / abyss_web_server1.0 – 1.0
- aprelium_technologies / abyss_web_server1.0.3 – 1.0.3