BOA Web Server 0.94.14 is susceptible to arbitrary file access. The server allows the injection of "../.." using the FILECAMERA variable sent by GET to read files with root privileges and without using access credentials.Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view