|
The RealPage Module Upload ActiveX control contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the Upload() method fails to restrict certain property values, which will allow remote attackers to use a combination of SourceFile filenames and DestURL http URLs to read arbitrary files.
|