From: joetestaHUSHMAIL.COM
Date: Mon Feb 05 2001 - 14:44:59 CST

    Vulnerability in Picserver


    Picserver is a specialized webserver available from http://www.informs.com
    and http://www.zdnet.com. A vulnerability exists which allows a remote
    user to break out of the web root using relative paths (ie: '..', '...').


            http://localhost:7000/../[file outside web root]
            http://localhost:7000/.../[file outside web root]


    No quick fix is possible.

        Vendor Status

    Information Management Specialists, Inc. was contacted via
    <pcprodsinforms.com> and <servicesinforms.com> on Monday, January 29,
    2001. No reply was received.

            - Joe Testa ( e-mail: joetestahushmail.com / AIM: LordSpankatron

