22-04-2010
Elastix "id_nodo" Local File Inclusion Vulnerability
Input passed via the "id_nodo" parameter to help/frameRight.php is not properly verified before being used. This can be exploited to disclose the content of arbitrary local files via directory traversal attacks.
 
 
 

back