Files
CVEs-PoC/2019/CVE-2019-6500.md
T
2025-09-29 21:09:30 +02:00

722 B

CVE-2019-6500

Description

In Axway File Transfer Direct 2.7.1, an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request with %2e instead of '.' characters, as demonstrated by an initial /h2hdocumentation//%2e%2e/ substring.

POC

Reference

No PoCs from references.

Github