MetaProducts Offline Explorer 1.x - FileSystem Disclosure
Author: Dodger
type: remote
platform: windows
port:
date_added: 2000-12-07
date_updated: 2012-08-13
verified: 1
codes: CVE-2001-0038;OSVDB-12267
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/2084/info
MetaProducts Offline Explorer is an application that allows a user to download the contents of a website or FTP site for offline browsing at a later time.
It is possible to view the full contents of the directory structure of a system Offline Explorer resides on. By default, Offline Explorer listens on port 800. A remote user may retrieve a directory listing and browse its contents without any authorization whatsoever by issuing a GET request followed by a corresponding physical or logical drive letter.
Eg.
http://target:800/C:/
will reveal a directory listing for drive C.