SL_site Gallerie.PHP Information Disclosure Vulnerability

SL_site is prone to an information-disclosure vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to retrieve arbitrary image files. This may be done by using directory-traversal sequences ('../') from the vulnerable system in the context of the application.

Information obtained by exploiting this issue may aid malicious users in further attacks.


 

Privacy Statement
Copyright 2010, SecurityFocus