Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

eshare Expressions Directory Traversal Vulnerability

A directory traversal vulnerability has been discovered in the eshare Expressions, which may potentially disclose known files to remote attackers. This is due to insufficient validation of strings passed in web requests.

An attacker who submits a specially crafted web request containing double dot slash (../) character sequences may be able to browse known files residing on a vulnerable host.







 

Privacy Statement
Copyright 2008, SecurityFocus