generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Six-webboard | Sixhead | 2.01 (including) | 2.01 (including) |
References