Falcon Web Server Traversal
---------------------------

CVE Number: 
None

Details:
The Falcon web server was found to be vulnerable to a dot-dot attack, which
allows for the attacker to view files outside the web directory.

Fix:
It is recommended that the Falcon web server be upgraded to version 1.0.0.1008
or higher, which eliminates the problem.

Related URLs:
http://razor.bindview.com/publish/advisories/adv_falcon.html
http://www.blueface.com/products.html#fws

$Id: falcon-dotdot,v 1.1 2000/11/21 16:02:07 loveless Exp $
