CVE-2010-2079 Information

Description

DataTrack System 3.5 allows remote attackers to bypass intended restrictions on file extensions and read arbitrary files via a trailing backslash in a URI as demonstrated by (1) web.config\ and (2) .ascx\ files.

Reference

http://cross-site-scripting.blogspot.com/2010/05/datatrack-system-35-persistent-xss.html http://packetstormsecurity.org/1005-exploits/datatrackserver35-xss.txt https://exchange.xforce.ibmcloud.com/vulnerabilities/58735

Share on: