Directory traversal vulnerability in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to read arbitrary files via an HTTP request with ".." (dot-dot) sequences containing URL-encoded forward slash ("%2F") characters.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/10373.php | vdb entry vendor advisory |
http://www.idefense.com/application/poi/display?id=49&type=vulnerabilities&flashstatus=true | third party advisory |
http://www.securityfocus.com/bid/5968 | vdb entry |