Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

MailReader.com NPH-MR.CGI File Disclosure Vulnerability

A vulnerability exists in Mailreader.com which may enable remote attackers to disclose the contents of arbitrary webserver readable files. An attacker may exploit this issue by submitting a malicious web request containing dot-dot-slash (../) directory traversal sequences. The request must be for a known resource, and the file request must be appended by a null byte (%00).







 

Privacy Statement
Copyright 2008, SecurityFocus