COMMAND
ServerWorx
SYSTEMS AFFECTED
Soft Lite ServerWorx 3.0
PROBLEM
Joe Testa found following. A vulnerability exists which allows a
remote user to break out of the web root using relative paths (ie:
'..', '...'):
http://localhost/../[file outside web root]
http://localhost/.../[file outside web root]
SOLUTION
Are you running ServerWorx 5.0? If you try using this instead,
you will see that any attempt to access a file outside the root of
the web will show an "access denied" message. Authors have now
dropped support for ServerWorx 3, and suggest to all their users
to move to the new version.