Directory traversal vulnerability in FileSeek.cgi allows remote attackers to read arbitrary files via a ....// (modified dot dot) in the (1) head or (2) foot parameters, which are not properly filtered.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/8858.php | patch vendor advisory vdb entry |
http://archives.neohapsis.com/archives/vuln-dev/2002-q2/0132.html | patch vendor advisory mailing list exploit |