Heap
01-02-08, 21:35
Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to read arbitrary files via a .. (dot dot) in the uri parameter to dispatcher.php in (1) examples/dispatcher/framework/, (2) examples/dispatcher/, (3) examples/wizard/, and (4) PHP/, different vectors than CVE-2008-????.
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0521)
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0521)