Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:17174
HistoryJun 04, 2007 - 12:00 a.m.

[Full-disclosure] Full Path Disclosure eqDKP 1.3.2c and prior

2007-06-0400:00:00
vulners.com
21

eqDKP 1.3.2c and prior 'compare' variable reveals the full path because
eqdkp fails to properly sanitize user-supplied input

Example: /path-to-eqdkp/listmembers.php?compare=%00


Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/