CERN httpd Double Slash Protected Webpage Bypass - does anyone know how to block this please?
The remote web server allows an attacker to access protected web pages by replacing slashes in the URL with '//' or '/./', which is a known problem in older versions of CERN web server.
Contact the web server vendor for an update or tighten its filtering rules to reject patterns such as :
//*
*//*
/./*
*/./*