Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

QuiXplorer Item Parameter Directory Traversal Vulnerability

QuiXplorer is prone to a directory traversal vulnerability. The issue occurs if a remote attacker sends a request to the application for a file containing directory traversal character sequences through the 'item' parameter. If successful, the attacker can access arbitrary files on a vulnerable computer in the context of the affected server.

QuiXplorer versions 2.3 and prior are prone to this issue.







 

Privacy Statement
Copyright 2009, SecurityFocus