Bajie HTTP web server 0.30a allows remote malicious users to read arbitrary files via a URL that contains a "....", a variant of the dot dot directory traversal attack.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
bajie java http server 1.0 |