
Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP request.
Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP request.
Packetstorm publication at https://packetstormsecurity.com/files/25837/Colbalt-RAQ-v4.txt.html
SecurityFocus publication at https://www.securityfocus.com/bid/4208
Alex Hernandez aka (@_alt3kx_)
The vendor was notified
Posted List^s Security cobalt:
[email protected] &
[email protected]
http://www.cobalt.com