Yaws Webserver 1.55 and previous versions allows remote malicious users to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
yaws webserver 1.52 |
||
yaws webserver 1.53 |
||
yaws webserver 1.50 |
||
yaws webserver 1.51 |
||
yaws webserver 1.54 |
||
yaws webserver 1.55 |