Summary
It is possible to access protected web pages
by changing / with // or /./
This was a bug in old versions of CERN web server
A work around consisted in rejecting patterns like:
//*
*//*
/./*
*/./*
Solution
Upgrade your web server or tighten your filtering rules
Severity
Classification
-
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities
- IBM WebSphere Application Server (WAS) XSS and CSRF Vulnerabilities
- Kolibri Webserver 'HEAD' Request Processing Buffer Overflow Vulnerability
- IBM WebSphere Application Server IVT Cross Site Scripting Vulnerability
- Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability
- IBM WebSphere Application Server 'plugin-key.kdb' Information Disclosure Vulnerability