Directory Pro Arbitrary File Disclosure Vulnerability

Webdirectory Pro is a web application used to create a searchable directory of links developed by Cosmicperl.

Webdirectory Pro contains an input validation vulnerability which may lead to disclosure of sensitive information to attackers. The value of the 'show' variable is not properly validated and can be used to force 'directorypro.cgi' to output the contents of an arbitrary webserver-readable file to a remote attacker.

This is due to a lack of checks for NULL bytes in user-supplied data.


 

Privacy Statement
Copyright 2010, SecurityFocus