dirLIST Multiple Local File Include and Arbitrary File Upload Vulnerabilities
13 Aug. 2012
Summary
dirLIST is prone to multiple local file-include vulnerabilities and an arbitrary-file upload vulnerability because the application fails to sufficiently sanitize user-supplied input.
Vulnerable Systems:
*dirLIST Multiple Local File Include and Arbitrary File Upload Vulnerabilities
An attacker can exploit these issues to upload arbitrary files onto the web server, execute arbitrary local files within the context of the web server, and obtain sensitive information.
Vendor Status:
Currently we are not aware of any vendor-supplied patches