Directory traversal vulnerability in folderview.asp for Blue-Collar Productions i-Gallery 3.3 allows remote attackers to read arbitrary files and directories via the folder parameter.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2005/0825 | vdb entry |
http://www.securityfocus.com/bid/14000 | vdb entry |
http://marc.info/?l=bugtraq&m=111936111630489&w=2 | mailing list |