PHP ImgList Directory Traversal Vulnerability

PHP ImgList allows a user to generate a web gallery of image files.

PHP ImgList does not adequately filter '../' sequences from web requests, making it prone to directory traversal attacks. This vulnerability could be exploited to effectively disclose any file on a host running the affected software.


 

Privacy Statement
Copyright 2010, SecurityFocus