Description
Directory traversal vulnerability in Aldo's Web Server (aweb) 1.5 allows remote attackers to view arbitrary files via a .. (dot dot) in an HTTP GET request.
Affected products
- aldostools / aldo's_web_server1.5 – 1.5
References
- MISChttp://www.securityfocus.com/bid/10262
- MAILING_LISThttp://marc.info/?l=bugtraq&m=108360629031227&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/11542
- MISChttp://www.osvdb.org/5881
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/16048
- MISChttp://www.oliverkarow.de/research/AldosWebserverMultipleVulns.txt