vendor:
KML share 1.1
by:
milw0rm.com
N/A
CVSS
N/A
Remote File Disclosure
CWE
Product Name: KML share 1.1
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Unknown
2007
KML share 1.1 (region.php layer) Remote File Disclosure Vulnerability
The KML share 1.1 script, specifically the region.php layer, is vulnerable to remote file disclosure. By exploiting this vulnerability, an attacker can disclose sensitive files from the target system. An example of the exploit is shown below:POC : region.php?layer=../../../../../../../etc/passwd%00
Mitigation:
Unknown