Web4Future Portal Solutions - 'Arhiva.php' Directory Traversal
Author: r0t
type: webapps
platform: php
port:
date_added: 2005-12-05
date_updated: 2013-07-10
verified: 1
codes: CVE-2005-4039;OSVDB-21423
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/15718/info
Portal Solutions is prone to a directory traversal vulnerability. This is due to a lack of proper sanitization of user-supplied input.
This issue may be leveraged to read arbitrary files on an affected computer with the privileges of the Web server. An attacker can employ directory traversal sequences to disclose arbitrary files.
http://www.example.com/arhiva.php?dir=../