Directory traversal vulnerability in sendform.cgi 1.44 and earlier allows remote attackers to read arbitrary files by specifying the desired files in the BlurbFilePath parameter.
| Software | From | Fixed in |
|---|---|---|
| rod_clark / sendform.cgi | 1.4.1 | 1.4.1.x |
| rod_clark / sendform.cgi | 1.4 | 1.4.x |
| rod_clark / sendform.cgi | 1.4.2 | 1.4.2.x |
| rod_clark / sendform.cgi | 1.4.4 | 1.4.4.x |
| rod_clark / sendform.cgi | 1.4.3 | 1.4.3.x |