Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrary files under the web root by appending ::$DATA to the end of an HTTP GET request, which accesses the alternate data stream.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Easy_address_book | Efs_software | 1.2 (including) | 1.2 (including) |