httpdx 1.4.5 - dot Character Remote File Disclosure

EDB-ID:

34846


Author:

Dr_IDE

Type:

remote


Platform:

Windows

Date:

2009-10-09


source: https://www.securityfocus.com/bid/44141/info

The 'httpdx' application is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to view the source code of files in the context of the server process. This may aid in further attacks.

Versions prior to httpdx 1.4.6b are vulnerable.

The following example URI are available:

http://www.example.com/index.html.
http://www.example.com/test.py.
http://www.example.com/test.php.