CVE-2012-5100 Information

Description

Directory traversal vulnerability in HServer 0.1.1 allows remote attackers to read arbitrary files via a (1) ..5c (dot dot encoded backslash) or (2) 2e2e5c (encoded dot dot backslash) in the PATH_INFO.

Reference

http://archives.neohapsis.com/archives/bugtraq/2012-01/0028.html http://www.securityfocus.com/bid/51286 https://exchange.xforce.ibmcloud.com/vulnerabilities/72138

Share on: