|
|
| |
| Offline Explorer is a popular Offline Web Browser. It's fast, flexible, easy to use, and does its job well. Nevertheless, it also has a big security hole; the program allows remote attackers to access any locally available files on a remote system. |
| |
Credit:
The information has been provided by Dodger.
|
| |
Vulnerable systems:
Offline Explorer version 1.4
Immune systems:
Offline Explorer version 1.4 Service Release 2
By accessing the following URL:
http://host.example.com:800/C:/
It is possible to access the mentioned hard drive and read all available files there.
|
|
|
|
|