[Full-disclosure] Full Path Disclosure eqDKP 1.3.2c and prior
kefka
kefka at kevinbeardsucks.com
Mon Jun 4 05:56:45 BST 2007
eqDKP 1.3.2c and prior 'compare' variable reveals the full path because
eqdkp fails to properly sanitize user-supplied input
Example: /path-to-eqdkp/listmembers.php?compare=%00
Full-Disclosure is hosted and sponsored by Secunia.