CVE-2010-2676 Information

Description

Multiple directory traversal vulnerabilities in index.php in Open Web Analytics (OWA) 1.2.3 might allow remote attackers to read arbitrary files via directory traversal sequences in the (1) owa_action and (2) owa_do parameters.

Reference

http://packetstormsecurity.org/1003-exploits/owa123-lfirfi.txt http://www.exploit-db.com/exploits/11903 http://www.ITSecTeam.com/en/vulnerabilities/vulnerability26.htm http://www.openwebanalytics.com/?p=87 https://exchange.xforce.ibmcloud.com/vulnerabilities/57240

Share on: