Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/5081 | vdb entry vendor advisory |
http://www.iss.net/security_center/static/9414.php | vdb entry vendor advisory |
http://archives.neohapsis.com/archives/bugtraq/2002-06/0265.html | vendor advisory mailing list exploit |