[Full-disclosure] Full Path Disclosure eqDKP 1.3.2c and prior

kefka kefka at kevinbeardsucks.com
Mon Jun 4 05:56:45 BST 2007


eqDKP 1.3.2c and prior 'compare' variable reveals the full path because 
eqdkp fails to properly sanitize user-supplied input

Example:  /path-to-eqdkp/listmembers.php?compare=%00




Full-Disclosure is hosted and sponsored by Secunia.