forked from offensive-security/exploitdb
-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy path21879.txt
More file actions
executable file
·12 lines (8 loc) · 772 Bytes
/
Copy path21879.txt
File metadata and controls
executable file
·12 lines (8 loc) · 772 Bytes
1
2
3
4
5
6
7
8
9
10
11
12
source: http://www.securityfocus.com/bid/5828/info
A vulnerability has been reported for the Sun ONE Starter Kit 2.0 and ASTAware SearchDisc. The Starter Kit includes a search engine facility provided for easy information retrieval. The search engine included with the Starter Kit is a modified version of ASTAWare SearchDisc. Reportedly, the search engine is vulnerable to directory traversal attacks.
An attacker can use the information obtained through this manner to launch potentially destructive attacks against a vulnerable system.
This vulnerability affects both the Sun ONE Starter Kit and ASTAware SearchDisc.
http://target:6015/../../../../../
http://target:6016/../../../../../
http://SearchDisk:6017/etc/Password
http://SearchDisk:6017/etc/Root