The Falcon Web Server v2.0 for Windows 2000 allows remote users to gain read access of known password protected files residing on a Falcon Web Server.
a16db8592601cc92d0e16282473fe839385c6245b47e4a65a486a7b596cdc3d3
--[ Falcon Web Server Unauthorized File Disclosure Vulnerability ]--
--[ Type
File Disclosure
--[ Release Date
May 26, 2002
--[ Product / Vendor
Falcon Web Server is a desktop web server capable of running a small /
medium website with a typical load of up to 50-80 hits per minute. The
server has the ability to execute ISAPI and WinCGI applications from
virtual directories.
https://www.blueface.com
--[ Summary
Due to a flaw in Falcon Web Server 2.0 for Windows, it is possible for a
user to gain read access of known password protected files residing on a
Falcon Web Server host.
https://host//protectedfolder/
--[ Tested
Windows 2000 / Falcon Web Server v2.0
--[ Vulnerable
Falcon Web Server v2.0 (And may be other.)
--[ Disclaimer
https://www.securityoffice.net is not responsible for the misuse or
illegal use of any of the information and/or the software listed on this
security advisory.
--[ Author
Tamer Sahin
ts@securityoffice.net
https://www.securityoffice.net
All our advisories can be viewed at https://www.securityoffice.net/articles/
Please send suggestions, updates, and comments to
feedback@securityoffice.net
(c) 2002 SecurityOffice
This Security Advisory may be reproduced and distributed, provided that
this Security Advisory is not modified in any way and is attributed to
SecurityOffice and provided that such reproduction and distribution is
performed for non-commercial purposes.
Tamer Sahin
https://www.securityoffice.net