Описание
Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a full pathname in the file parameter to index.php.
Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a full pathname in the file parameter to index.php.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2012-1790
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73509
- http://code.google.com/p/webgrind/issues/detail?id=66
- http://packetstormsecurity.org/files/110216
- http://www.exploit-db.com/exploits/18523
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2012-5075.php
Связанные уязвимости
nvd
почти 14 лет назад
Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a full pathname in the file parameter to index.php.