Description
Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter.
Affected products
- Apple / darwin_streaming_server4.1.2 – 4.1.2
- Apple / quicktime_streaming_server4.1.1 – 4.1.1
Exploits & proofs of concept
- exploit-dbApple QuickTime/Darwin Streaming Server 4.1.x - 'parse_xml.cgi' File Disclosureby Joe Testa
Updated 9m ago · 8 sources