|
|
|
|
| |
| ByteHoard is "an online file storage system, written in PHP. Includes automatic compression, multiple file views, fully-featured admin interface, global & user space limiters, authentication, ability to send files via email and more". A directory revealing vulnerability has been found in the product allowing remote attackers to reveal the content of directories that reside under HTTP root directory. |
| |
Credit:
The information has been provided by Chris Sharp.
|
| |
Vulnerable systems:
* ByteHoard version 0.71
By accessing the following URL: http://victim.com/bytehoard/files.inc.php, it is possible to determine the content of directories residing under the HTTP root directory.
|
|
|
|
|