Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read and modify arbitrary files, and list arbitrary directories via ..\ (dot dot backslash) sequences in the BrowsePath parameter.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2007/0023 | vdb entry |
http://securitytracker.com/id?1017447 | vdb entry exploit |
http://www.securityfocus.com/bid/21786 | vdb entry exploit |
http://secunia.com/advisories/23585 | third party advisory |
http://www.kapda.ir/advisory-458.html | exploit vendor advisory |