Directory traversal vulnerability in downloadexcel.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the fn parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Link | Tags |
---|---|
http://secunia.com/advisories/23109 | third party advisory vendor advisory |
http://www.vupen.com/english/advisories/2006/4723 | vdb entry |