Directory traversal vulnerability in Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) allows remote malicious users to read or modify arbitrary files via an illegal character in the middle of a .. (dot dot) sequence in the parameters (1) _browser_out or (2) _out_file.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
jon hedley alienform2 1.5 |