The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information by uploading a file, which reveals the path in a success message.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0852.html | mailing list exploit vendor advisory |
http://aluigi.altervista.org/adv/actp-adv.txt | exploit vendor advisory |
http://marc.info/?l=bugtraq&%3Bm=109597139011373&%3Bw=2 | mailing list |
http://www.osvdb.org/10235 | vdb entry |
http://securitytracker.com/id?1011406 | exploit vdb entry vendor advisory |