Description
Acunetix uploaded a ZIP file containing a symlink to /etc/passwd. It looks like that web application processed this file and returned the contents of /etc/passwd in response.
Remediation
The web application should filter symlinks included inside ZIP files.
References
Related Vulnerabilities
jQuery File Upload unauthenticated arbitrary file upload
Typo3 Install Tool publicly accessible
WordPress Plugin Service Finder-Provider and Business Listing Local File Disclosure (3.0)
WordPress Plugin Export any WordPress data to XML/CSV Arbitrary File Upload (0.9)
WordPress Plugin WP Easy Gallery 'add-gallery.php' Arbitrary File Upload (1.8)