Reported February 13, 2002, by SNS Research.
Falcon Web Server for Windows
An authentication circumvention vulnerability exists in BlueFace’s Falcon Web Server for Windows. A problem in the parsing of requests made to protected directories can let an attacker circumvent the Web server’s authentication scheme and access any file in a protected directory without supplying proper credentials. By supplying an additional backslash at the beginning of the virtual path, an intruder can bypass authentication. For example, an attacker can bypass authentication of the "http://localhost/test" protected directory by accessing “http://localhost//test.”
The vendor, BlueFace, has been notified and will release build 220.127.116.111 to correct this problem.
Discovered by SNS Research.