Vulnerable Systems:
* Visual Synapse HTTP Server 1.0 RC3
* Visual Synapse HTTP Server 1.0 RC2
* Visual Synapse HTTP Server 1.0 RC1
* Visual Synapse HTTP Server 0.60 and previous releases
A Directory Traversal vulnerability exists in Visual Synapse HTTP Server. This is possible to trigger by sending a specially-crafted URL request containing "dot dot" sequences (/..\).
The source code of the server warns about possible security issues and that it is not suitable for production environments yet. These warning must be taken seriously. Any application using this source is vulnerable unless the code is patched. Any machine running the compiled HTTPD Server demo is vulnerable as well, unless the application is replaced with an up-to-date and patched version.