CVE-2007-6378
Directory traversal vulnerability in upload.dll in BadBlue 2.72b and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the filename parameter.
Date published : 2007-12-14
http://www.securityfocus.com/bid/26803
http://www.securityfocus.com/archive/1/484834/100/0/threaded
