CVE-2011-1569
05.04.2011, 15:19
download.aspx in Douran Portal 3.9.7.8 allows remote attackers to obtain source code of arbitrary files under the web root via (1) a trailing ".", (2) a trailing space, or (3) mixed case in the FileNameAttach parameter.Enginsight
Vendor | Product | Version |
---|---|---|
douran | portal | 3.9.7.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References