Hot Links - Exposure of Sensitive Information via Direct Request with Modified dl Parameter
The (1) dlback.php and (2) dlback.cgi scripts in Hot Links allow remote attackers to obtain sensitive information and download the database via a direct request with a modified dl parameter.
Jeebles Directory 2.9.60 - Path Traversal via Download.php Query String
Absolute path traversal vulnerability in download.php in Jeebles Directory 2.9.60 allows remote attackers to read arbitrary files via a full pathname in the query string. NOTE: some of these details are obtained from third party information.