chienthan9x / wavsep

Automatically exported from code.google.com/p/wavsep
0 stars 0 forks source link

LFI test case 37 & similar test cases don't function under linux #10

Open GoogleCodeExporter opened 9 years ago

GoogleCodeExporter commented 9 years ago
Case 37 and a few similar test cases (which perform slash validation) don't 
work properly on Linux.

Although under Windows the could be bypassed by replacing / with \, or by 
accessing one of the files installed by default in tomcat's root directory 
(minor), in Linux that does not seem to work.

For the moment - the best way to reproduce the benchmark results is to use 
wavsep on windows XP or windows 7 (right click and run tomcat as admin), and 
although the vast majority of test cases will work on Linux, several LFI test 
cases might not.

Reported by Tasos Laskos (arachni's developer).

Original issue reported on code.google.com by sectoola...@gmail.com on 25 Jul 2012 at 8:41