exploit-db-mirror/exploits/windows/remote/20886.txt
Offensive Security d304cc3d3e DB: 2017-11-24
116602 new exploits

Too many to list!
2017-11-24 20:56:23 +00:00

7 lines
No EOL
334 B
Text

source: http://www.securityfocus.com/bid/2788/info
Submitting a specially crafted GET request for a known file (.php, .pl, or .shtml), could cause OmniHTTPD to disclose the source code of the requested resource. The GET requested would have to be appended with the Unicode equivalent of a space.
Example:
GET /filename.php%20