Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the file parameter.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/11987 | vdb entry |
http://www.securityfocus.com/bid/7559 | vdb entry |
http://marc.info/?l=bugtraq&m=105276130814262&w=2 | mailing list |