Arbitrary file existence disclosure in Action Pack (CVE-2014-7818)
groups.google.com
Arbitrary file existence disclosure in Action Pack (CVE-2014-7818)
1–2 of 2 posts
Re: Arbitrary file existence disclosure in Action Pack (CVE-2014-7818)
#2Wow, this is trivial to exploit -- I recommend people apply the patches immediately. You can't leak file contents, but it's otherwise a fairly standard path traversal attack.