This host is running Tiny Server and is prone to arbitrary file disclosure vulnerability.
Successful exploitation could allow attackers to perform directory traversal attacks and read arbitrary files on the affected application. Impact Level: Application
No solution or patch was made available for at least one year since disclosure of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade to a newer release, disable respective features, remove the product or replace the product by another one.
The flaw is due to an input validation error in application, which allows attackers to read arbitrary files via a ../(dot dot) sequences.
Tiny Server version 1.1.5
- IBM WebSphere Application Server 'plugin-key.kdb' Information Disclosure Vulnerability
- IIS IDA/IDQ Path Disclosure
- IBM WebSphere Application Server (WAS) Multiple Vulnerabilities 01 - March 2011
- bozohttpd Security Bypass Vulnerability
- IBM WebSphere Application Server Administration Directory Traversal Vulnerability