Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
Arbitrary file existence disclosure in Action Pack (CVE-2014-7818)
(opens in new tab)
(groups.google.com)
4 points
bensedat
11y ago
1 comments
Save
Share
1 comments
1 comments · 1 top-level
top
newest
oldest
ShaneWilton
11y ago
Wow, this is trivial to exploit -- I recommend people apply the patches immediately. You can't leak file contents, but it's otherwise a fairly standard path traversal attack.
j
/
k
navigate · click thread line to collapse