Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

DynaWeb Developers MMS Gallery 'id' Parameter Multiple Directory Traversal Vulnerabilities

MMS Gallery is prone to multiple directory-traversal vulnerabilities that let attackers access arbitrary files because the application fails to sufficiently sanitize user-supplied input.

An attacker can exploit these issues using directory-traversal strings ('../') to download arbitrary files with the privileges of the webserver process. Information obtained may aid in further attacks.

MMS Gallery 1.0 is reported affected; other versions may be vulnerable as well.







 

Privacy Statement
Copyright 2009, SecurityFocus