Encoded directory traversal vulnerability in Dino's web server 2.1 allows remote malicious users to read arbitrary files via ".." (dot dot) sequences with URL-encoded (1) "/" (%2f") or (2) "\" (%5c) characters.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
funsoft dinos webserver 1.2 |