18610exploit
http://www.exploit-db.com/exploits/18610 CVE-2012-5335
Tiny Server 1.1.5 - Arbitrary File Disclosure
Record summary
CVE-2012-5335 has a selected CVSS score of 4.0; EIP currently links 1 catalogued exploit.
Description
Directory traversal vulnerability in Tiny Server 1.1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the URI of an HTTP request.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBTiny Server 1.1.5 - Arbitrary File DisclosureExploitDB exploitby KaHPeSeSeNot analyzed1 file
References
580586vdb entry
http://www.osvdb.org/80586 52541vdb entry
http://www.securityfocus.com/bid/52541 tiny-server-directory-traversal(74114)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/74114 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-5335