|
getIntranet contains a flaw that may allow a remote attacker to manipulate arbitrary directories. The issues is due to the folder_detail.asp script not properly sanitizing user input and authenticating requests. By modifying the 'id' or 'lid' parameters passed to the script, an attacker could view or delete any folder.
|