MyServer 0.8.9 and previous versions does not properly handle uppercase characters in filename extensions, which allows remote malicious users to obtain sensitive information (script source code) via a modified extension, as demonstrated by post.mscgI.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
myserverproject myserver |