CGI Script Center Auction Weaver...

- AV AC AU C I A
发布: 2000-10-12
修订: 2025-04-13

It is possible for a remote user without any proper credentials to view the contents of any known file residing on a system running CGI Script Center Auction Weaver. The form fields username and bidfile used in conjunction with null characters can be used to gain read access to arbitrary files by utilizing the double dot ".." method.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息