WinGate 5.2.3 build 901 and 6.0 beta 2 build 942, and other versions such as 5.0.5, allows remote attackers to read arbitrary files from the root directory via a URL request to the wingate-internal directory.
| Software | From | Fixed in |
|---|---|---|
| qbik / wingate | 6.0_beta_2 | 6.0_beta_2.x |
| qbik / wingate | 5.0.5 | 5.0.5.x |
| qbik / wingate | 5.2.3 | 5.2.3.x |