Title: Arbitrary file retrieval
Created on 2018-05-08.08:07:36 by deadshot, last changed 2018-08-24.17:01:32 by jeff.allen.

File contains POC sceen shots of hot to retrieve arbitrary files
msg11964 (view) Author: Jeff Allen (jeff.allen) Date: 2018-05-08.22:13:45
Thanks for your interest in the security of and for going to the trouble of assembling this report.

If there were a problem here, it would be with, not with But I think there isn't.

In the page you've generated, these (relative) links don't actually go anywhere. However, a working page much like it is accessible from the search page: Follow the BROWSE link to:

These appear all to be files that is happy to give you.
