Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:17346
HistoryJun 26, 2007 - 12:00 a.m.

SHTTPD V1.38 server source code disclosure

2007-06-2600:00:00
vulners.com
80

SHTTPD V1.38 server source code disclosure

link:http://shttpd.sourceforge.net/

info: The vulnerability is caused due to a parser error of the filename

extension supplied by the user in the URL.
This can be exploited to retrieve the source code of script files.

POC: http://127.0.0.1/test.php%20

Bug Found By: Shay priel aka Prili - imprili[at]gmail.com