Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Webspirs |
Silverplatter |
3.3.1 (including) |
3.3.1 (including) |
References