Great Reviews!Need help setting up your website, installing Apache, PHP, MySQL, or PhpNuke?Need help customizing or designing scripts?Please contact me via the Contact Us option for further details and pricing.
DESCRIPTION: fuzion has discovered a vulnerability in Seagull PHP Framework, which can be exploited by malicious people to disclose sensitive information.
Input passed to the "files" parameter in www/optimizer.php is not properly sanitised before being used. This can be exploited to display arbitrary files through directory traversal attacks. The vulnerability is confirmed in version 0.6.3 minimal and 0.6.3 full package. Other versions may also be affected.
SOLUTION: Edit the source code to ensure that input is properly sanitised.
PROVIDED AND/OR DISCOVERED BY: fuzion
ORIGINAL ADVISORY: http://milw0rm.com/exploits/4980
Posted on Friday, January 25, 2008 @ 21:25:21 EST by Raven