7.5
CVSSv2

CVE-2002-1238

Published: 12/11/2002 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Peter Sandvik's Simple Web Server 0.5.1 and previous versions allows remote malicious users to bypass access restrictions for files via an HTTP request with a sequence of multiple / (slash) characters such as www.example.com///file/.

Vulnerable Product Search on Vulmon Subscribe to Product

peter sandvik simple web server

Exploits

source: wwwsecurityfocuscom/bid/6145/info Simple Web Server does not properly sanitize web requests By adding a slash-slash sequence ('//') to a URI, it is possible for an attacker to disclose files on the vulnerable web server, effectively bypassing any access controls servercom///secret/file ...