|
|
| |
| Two security vulnerabilities have been found in Ultraseek Server. These vulnerabilities allow malicious users to find out the absolute path of HTML files and the source code of HTML files and Ultraseek Server add-ons. |
| |
Credit:
The information has been provided by china nsl.
|
| |
Vulnerable systems:
Ultraseek Server 3.0
Exploit:
True directory path discovery:
By sending the following to an Ultraseek Server it is possible to find out what is the true directory path used by the Ultraseek server:
http://target.example.com:8765/null.html
View the content of files:
By requesting the following:
http://target.example.com:8765/index.html/
It is possible to cause the Ultraseek Server to return the content of HTML files and Ultraseek Server add-ons.
|
|
|
|
|
|
|
|