CVE-2008-0480

Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary directories, and .txt and .zip files, via a …..\ in the sub parameter to (1) RTE_file_browser.asp or (2) file_browser.asp.

Date published : 2008-01-29

http://www.securityfocus.com/bid/27419

http://www.securityfocus.com/archive/1/486866/100/0/threaded