exploit-db-mirror/exploits/windows/remote/19753.txt
Offensive Security d304cc3d3e DB: 2017-11-24
116602 new exploits

Too many to list!
2017-11-24 20:56:23 +00:00

7 lines
No EOL
610 B
Text

source: http://www.securityfocus.com/bid/989/info
Microsoft's Personal Web Server and Front Page Personal Web Server will follow '/..../' strings in requested URLs, allowing remote users to obtain unauthenticated read access to files and directories on the same logical drive as the web content. Hidden files are viewable via this method, although the Front Page directory itself is not. The name and path of the desired file must be known to the attacker.
Note that while these programs support Windows 95, 98 and NT, only the Win9x versions are vulnerable.
http://target/..../directory/filename.ext