Miniwebsvr 0.0.6 - Directory traversal

Credit: Daniel Nystrm
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-Other

CVSS Base Score: 7.8/10
Impact Subscore: 6.9/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: Complete
Integrity impact: None
Availability impact: None

Hello! Miniwebsvr 0.0.6 suffers from a directory traversal flaw. "Exploit" : http://yoursite/..%00 Attack vector seems limited as you're only able to list one level down. Cheers, Daniel Nystrm, daniel.nystrom (at) xored (dot) net [email concealed] Fredrik Wessberg, fredd3 (at) hotmail (dot) com [email concealed]

