Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in the album parameter, and the target filename in the pic parameter.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0092.html | Exploit Patch |
http://www.securityfocus.com/archive/1/312966 | Exploit Patch |
http://www.securityfocus.com/bid/6929 | Exploit Patch |
http://www.iss.net/security_center/static/11429.php |
Configurations
Information
Published : 2003-12-30 21:00
Updated : 2008-09-05 13:36
NVD link : CVE-2003-1239
Mitre link : CVE-2003-1239
JSON object : View
CWE
Products Affected
wihphoto
- wihphoto