Beveiligingsadvies
CVE-2006-1201
CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations
Beschrijving
Directory traversal vulnerability in resetpw.php in eschew.net phpBannerExchange 2.0 and earlier, and other versions before 2.0 Update 5, allows remote attackers to read arbitrary files via a .. (dot dot) in the email parameter during a "Recover password" operation (recoverpw.php).