CVE-2007-5776 Information

Description

Directory traversal vulnerability in igallery.asp in Blue-Collar Productions i-Gallery 3.4 allows remote attackers to read arbitrary files via encoded backslash sequences in the d parameter as demonstrated by a \5c../../5c\ sequence.

Reference

http://osvdb.org/43628 http://securityreason.com/securityalert/3330 http://www.securityfocus.com/archive/1/482788/100/0/threaded http://www.securityfocus.com/bid/26348

Share on: