Description
|
|
Two vulnerabilities have been identified in Dwarf HTTP Server, which could be exploited by remote attackers to gain knowledge of sensitive information or execute arbitrary scripting code.
The first flaw is due to an input validation error when handling specially crafted filename extensions containing dot, space, slash and NULL characters, which could be exploited by remote attackers to display the source code of arbitrary scripts (e.g. JSP) instead of an expected HTML response.
The second issue is due to an input validation error when displaying error messages, which could be exploited by malicious people to conduct cross site scripting attacks via a specially crafted HTTP request.
|