CVE-2007-3365
HIGHmyserver < 0.8.9 - Sensitive Information Exposure via Case Sensitivity Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3365. PoCs published by Shay Priel.
AI-analyzed exploit summary The exploit describes an information-disclosure vulnerability in MyServer 0.8.9, where accessing a specific URI with a capital 'I' at the end exposes sensitive information. The advisory references a SecurityFocus BID but lacks detailed technical analysis or functional exploit code.
Description
MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions, which allows remote attackers to obtain sensitive information (script source code) via a modified extension, as demonstrated by post.mscgI.
Exploits (1)
The exploit describes an information-disclosure vulnerability in MyServer 0.8.9, where accessing a specific URI with a capital 'I' at the end exposes sensitive information. The advisory references a SecurityFocus BID but lacks detailed technical analysis or functional exploit code.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N