generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Six-webboard |
Sixhead |
2.01 (including) |
2.01 (including) |
References