Directory traversal vulnerability in BearShare 4.0.5 and 4.0.6 allows remote attackers to read files outside of the web root by hex-encoding the / (forward slash) or . (dot) characters.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Bearshare | Free_peers | 4.0.5 (including) | 4.0.5 (including) |
| Bearshare | Free_peers | 4.0.6 (including) | 4.0.6 (including) |