Description
Directory traversal vulnerability in textview.php in Anton Vlasov DoSePa 1.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) sequence or absolute file path in the file parameter.
Affected products
- anton_vlasov / dosepa1.0.4 – 1.0.4
References
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/30349
- EXPLOIThttps://www.exploit-db.com/exploits/2795
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2006/4576
- MISChttp://www.securityfocus.com/bid/21149
- VENDOR_ADVISORYhttp://secunia.com/advisories/22960
- MISChttp://www.craigheffner.com/security/exploits/dosepa.txt