CVE-2008-1400 Information

Description

Directory traversal vulnerability in the Net Inspector HTTP Server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to read arbitrary files via a ..\\ (dot dot backslash) or ../\ (dot dot slash) in the URI.

Reference

http://aluigi.altervista.org/adv/netinsp-adv.txt http://secunia.com/advisories/29421 http://www.securityfocus.com/archive/1/489704/100/0/threaded http://www.securityfocus.com/bid/28266 https://www.exploit-db.com/exploits/5269

Share on: