Easy File Sharing Web Server (1.2 NEW) vulns

Vulnerabilities in Easy File Sharing Web Server (1.2 NEW).

Vendor: <>
Version: 1.2 (new)
Date: Sep 22, 2003
Size: 2115KB
"Easy File Sharing Web Server contains several built-in systems including HTTP Web Server,multi-threads database system, Bulletin Board System, Server Script system, Password protection system. Users just need to install Easy File Sharing Web Server and no other software. All without additional configuration. 
You may create a virtual folder from your hard disk; visitors may upload/download files to/from it. Easy File Sharing Web Server is much easier to use than a typical FTP server."
Issue: 1. Flood-atack danger. 
2. View log-files and options.
(1) I have found some small vulnerabilities in the built - in forum.
- At creation new topic, field "Title:" permits to enter an empty symbol. Thus occurs potential danger of flood-attack.
- Field "Your Message:" has no fixed are long.
- The any user can look contents log-files.

- View options.ini

======[example option.ini]======
[Server] WebPages= DefaultPage=login.htm startup=1 AutoActive=1 Minimize=0 Savelog=1 Port=80 

Template=default showsys=0 showhide=0 expire=600 resume=1 smallpic=0 picsize=0 fileprotect=1 

[Email] SmtpPort=25 Account=wordsend 

Password=,207,194,202,217,216,214 NeedAuth=1 Subject=User Registration Information 

username=file-sharing web server <> [IP] Mode=0 

