byteHoard 0.7 and 0.71 allows remote attackers to list arbitrary files and directories via a direct request to files.inc.php.
Link | Tags |
---|---|
http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012801.html | mailing list exploit |
http://secunia.com/advisories/10082 | third party advisory patch |
http://www.securityfocus.com/bid/8910 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/13531 | vdb entry |
http://www.osvdb.org/2700 | vdb entry |