Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request with a sequence of multiple / (slash) characters such as http://www.example.com///file/.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Simple Web Server远程文件泄露漏洞
Vulnerability Description
Peter Sandvik's Simple Web是一款基于Linux的小型HTTP服务程序。 Simple Web服务程序没有正确过滤WEB请求,远程攻击者可以利用这个漏洞绕过访问控制以访问受限文件内容。 由于Simple Web服务程序不正确处理畸形URL请求,攻击者可以在URI中提交'//'字符来绕过访问限制,并访问文件内容,造成敏感信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A