Sybase PowerDynamo personal web server Directory traversal vulnerability

    Sybase PowerDynamo


    Sybase PowerDynamo personal web server


    Domas Mituzas  found that  Sybase PowerDynamo  personal web server
    knows how to handle ../../ queries.  One could see the whole  disk
    via  web  browser.   This  was  found  on  a  rather  new  release
    (  of  PD  personal  web  server,  that is included into
    Enterprise  Aplication  studio  and  together  with PowerDynamo in
    other boxes.   This "feature" works  both with static  and dynamic
    file sites (no check on database site).

    Of course, as  it is "personal"  web server, such  features may be
    left.  But as the same bugs were in MS and other servers, it is  a
    thing we should concern - why do software vendors not look at  old
    bugs of other products, so they could avoid theirs?


    Should be fixed.

