Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing . (dot) or (2) list directory contents via a trailing null character.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Xerver |
Xerver |
4.17h (including) |
4.17h (including) |
References