[24450] in bugtraq
BPM STUDIO PRO 4.2 DIRECTORY ESCAPE VULNERABILITY
daemon@ATHENA.MIT.EDU (][-][UNTER)
Wed Feb 27 23:06:26 2002
Message-ID: <007b01c1bf75$e367e400$4500a8c0@pepe>
From: "][-][UNTER" <lopht@tutopia.com>
To: <bugtraq@securityfocus.com>
Date: Wed, 27 Feb 2002 07:02:34 -0300
Hi bugtraq again...
Now i' ve found another vulnerability in BPM STUDIO PRO 4.2 http server
implementation.
Anyone can download any file in some host running this software simply like
performing this http request :
http://BPM-HOST/../../../../autoexec.bat
http server is not activated by default...
byes
-----------------------------------------------
][-][UNTER
Infobyte Security Research Crew
Buenos Aires, Argentina
-----------------------------------------------