faust Informatics FreeStyle chat 4.1 sr2 - Directory Traversal
Author: nemesystm
type: remote
platform: multiple
port:
date_added: 2001-05-25
date_updated: 2012-08-28
verified: 1
codes: CVE-2001-0615;OSVDB-1841
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/2776/info
Freestyle Chat server from Faust Informatics incorporates interactive chat functionality into websites.
Versions of Freestyle Chat are vulnerable to directory traversal attacks. This can allow a remote user to request files from outside the normal webserver directory scope.
Properly exploited, this could provide information useful in further attacks on the vulnerable host.
http://www.example.com/.../.../scandisk.log