Directory traversal vulnerability in BearShare 4.0.5 and 4.0.6 allows remote attackers to read files outside of the web root by hex-encoding the / (forward slash) or . (dot) characters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bearshare | Free_peers | 4.0.5 (including) | 4.0.5 (including) |
Bearshare | Free_peers | 4.0.6 (including) | 4.0.6 (including) |