My Postcards MagicCard.CGI Arbitrary...

- AV AC AU C I A
发布: 2002-06-15
修订: 2025-04-13

My Postcards is a commercial available eletronic postcard system. It is available for Unix and Linux Operating Systems. The magiccard.cgi script does not properly handle some types of input. As a result, it may be possible for a remote user to specify the location of a specific file on the system hosting the My Postcards software. Upon specifying the location of a file that is readable by the web server process, the user could disclose the contents of the specified file.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息