Enceladus Server Directory Traversal Vulnerability
12 Dec. 2002
Summary
Enceladus Server Suite is an Internet/Intranet lightweight Web and FTP Server for Windows, provides secure file sharing on any network. A security vulnerability in the product allows remote attackers to view the content of files residing outside the bounding HTML root directory.
Credit:
The information has been provided by Luca Ercoli.
Vulnerable systems:
* Enceladus Server Suite version 2.6.1
The web server has been found to contain a security flaw that allows attackers to traverse up the root directory and view/download files on the system.