PT-2002-2208 · Peter Sandvik · Peter Sandvik'S Simple Web Server
Published
2002-11-10
·
Updated
2017-07-11
·
CVE-2002-1238
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Peter Sandvik's Simple Web Server versions 0.5.1 and earlier
Description:
The issue allows remote attackers to bypass access restrictions for files by sending an HTTP request with a sequence of multiple / (slash) characters. For example, a request to "http://www.example.com///file/" could potentially access a restricted file.
Recommendations:
For versions 0.5.1 and earlier, consider restricting access to sensitive files and directories until a fix is available. As a temporary workaround, consider implementing additional access control mechanisms to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Peter Sandvik'S Simple Web Server