Interactive Story Directory...

- AV AC AU C I A
发布: 2001-07-15
修订: 2025-04-13

Interactive Story is a web-based application written in Perl and is distributed as freeware. Interactive Story does not filter '../' sequences from user input submitted to a hidden file called 'next'. Remote attackers may take advantage of this by crafting URLs that allow them to break out of webroot and view arbitrary web-readable files. The disclosed information may be used in further attacks on the host.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息