Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SL_site Gallerie.PHP Information Disclosure Vulnerability

SL_site is prone to an information-disclosure vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to retrieve arbitrary image files. This may be done by using directory-traversal sequences ('../') from the vulnerable system in the context of the application.

Information obtained by exploiting this issue may aid malicious users in further attacks.







 

Privacy Statement
Copyright 2009, SecurityFocus