download_script.asp in ASP Folder Gallery allows remote attackers to read arbitrary files via a filename in the file parameter.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/24345 | vdb entry exploit |
http://www.securityfocus.com/archive/1/470667/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34906 | vdb entry |
http://securityreason.com/securityalert/2793 | third party advisory |
http://osvdb.org/38372 | vdb entry |