exploit-db-mirror/exploits/cgi/webapps/22377.txt
Offensive Security 36c084c351 DB: 2021-09-03
45419 changes to exploits/shellcodes

2 new exploits/shellcodes

Too many to list!
2021-09-03 13:39:06 +00:00

5 lines
No EOL
554 B
Text

source: https://www.securityfocus.com/bid/7125/info
Kebi Academy 2001 does not sufficiently validate input supplied via URI parameters. As a result it has been reported that it is possible to retrieve arbitrary files which are readable by the web server. It has also been reported that it is possible to upload malicious files to the server. This could result in disclosure of sensitive information or execution of arbitrary commands in the context of the web server.
http://www.example.com/k/home?dir=/&file=../../../../../../../../etc/passwd&lang=kor