Hacker News new | ask | show | jobs
Arbitrary file existence disclosure in Action Pack (CVE-2014-7818) (groups.google.com)
4 points by bensedat 4243 days ago
1 comments

Wow, this is trivial to exploit -- I recommend people apply the patches immediately. You can't leak file contents, but it's otherwise a fairly standard path traversal attack.