Viewing arbitrary file from the file system using Eshare Expressions 4 server

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



There is a bug in Expressions server where you can view any file on the
drive that the server is installed on by using simple ../../

Example:
If eshare server Is installed at:
C:\eshare\expressions
And lets say this is an NT4.0 machine with os installed in c:\winnt
It is possible to pull win.ini file from winnt directory using 

Proto://domainname.com/../../../../../winnt/win.ini

Any file can be viewed in the manner.



[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux