|
Product: Nuca WebServer Version: 0.01 OffSite: http://www.geocities.com/nucainterface Problem: Directory traversal ------------------------------------------------ NucaWebServer - server, written in Delphi. This server have a large problem - Atacker may view all files on hard disk. The server does not process the entering data. http://[victim]/../existing_file Example: http://[victim]/../webserver.ini and you may be view webserver configuration. [Configuration] SSL=0 Port=80 Root=D:\webservers\Nms\web Authentic=0 Username= Password= www.overg.com www.dwcgr0up.com regards, Over G[DWC Gr0up]