Offline Explorer 1.4 before Service Release 2 allows remote attackers to read arbitrary files by specifying the drive letter (e.g. C:) in the requested URL.
Software | From | Fixed in |
---|---|---|
metaproducts / offline_explorer | 1.0x | 1.0x.x |
metaproducts / offline_explorer | 1.1x | 1.1x.x |
metaproducts / offline_explorer | 1.2x | 1.2x.x |
metaproducts / offline_explorer | 1.3x | 1.3x.x |