9 lines
No EOL
727 B
Text
9 lines
No EOL
727 B
Text
source: https://www.securityfocus.com/bid/4039/info
|
|
|
|
Portix-PHP is freely available web portal software. It is written in PHP and will run on most Unix and Linux variants.
|
|
|
|
Portix-PHP is prone to directory traversal attacks. The script view.php does not sufficiently filter '../' sequences from web requests, making it possible for an attacker to browse the filesystem of the host running the vulnerable software. Arbitrary web-readable files may be viewed by an attacker.
|
|
|
|
Successful exploitation may cause sensitive information to be disclosed to the attacker. Information gathered in this manner may be used to aid in further attacks against the host.
|
|
|
|
www.hostportix.com/index.php?l=forum/view.php&topic=../../../etc/passwd |