AnalogX SimpleServer:WWW 1.06 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack that uses the %2E URL encoding for the dots.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Simpleserver_www |
Analogx |
1.0.6 (including) |
1.0.6 (including) |
References