Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Hurr!C4Ne!

Researcher fromAJAX Security Team
#48883of 53,635
5Total CVSS
Vulnerabilities · 1
PT-2011-3226
5.0
2011-04-05
Douran · Douran Portal · CVE-2011-1569
**Name of the Vulnerable Software and Affected Versions** Douran Portal version 3.9.7.8 **Description** The issue allows remote attackers to obtain the source code of arbitrary files under the web root. This can be achieved through the "download.aspx" page by manipulating the `FileNameAttach` parameter with techniques such as appending a trailing ".", a trailing space, or using mixed case. **Recommendations** For Douran Portal version 3.9.7.8, consider restricting access to the "download.aspx" page until a fix is available, and avoid using the `FileNameAttach` parameter with potentially vulnerable inputs.