Description
Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system files by manipulating URL path segments. Attackers can use multiple '../' sequences to navigate outside the web root and retrieve sensitive configuration files like Windows system files.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Credits
Numan Türle
References
www.exploit-db.com/exploits/47666 (ExploitDB-47666)
www.genivia.com/ (Vendor Homepage)
web.archive.org/...ystalrs.com/crystal-quality-introduction/ (Archived Software Product Page)
www.vulncheck.com/...crystal-live-http-server-path-traversal (VulnCheck Advisory: Genivia Crystal Live HTTP Server 6.01 - 'Crystal Live HTTP Server' Path Traversal)