CVE-2005-2543 Information

Description

Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the download parameter.

Reference

http://marc.info/?l=bugtraq&m=112327874920062&w=2 http://www.securityfocus.com/bid/14479

Share on: