CVE-2011-1569
CVE-2011-1569
download.aspx in Douran Portal 3.9.7.8 allows remote attackers to obtain source code of arbitrary files under the web root via (1) a trailing ".", (2) a trailing space, or (3) mixed case in the FileNameAttach parameter.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/17011unverifiedexploitdbwww.exploit-db.com/exploits/17011unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://osvdb.org/71250http://secunia.com/advisories/43792http://securityreason.com/securityalert/8180https://exchange.xforce.ibmcloud.com/vulnerabilities/66177http://soroush.secproject.com/blog/2011/01/unrestricted_file_download_v1_0/http://www.exploit-db.com/exploits/17011http://www.securityfocus.com/archive/1/517085/100/0/threadedhttp://www.securityfocus.com/bid/46927