Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP request.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=101495944202452&w=2 | mailing list |
http://www.securityfocus.com/bid/4208 | vdb entry patch vendor advisory |
http://www.iss.net/security_center/static/8322.php | vdb entry vendor advisory |