This is a writeup describing a local file disclosure vulnerability in eCan v0.1. The vulnerability allows an attacker to read arbitrary files on the server via a path traversal attack in the 'show_source.php' script.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:eCan v0.1
No auth needed
Prerequisites:Access to the vulnerable web application