Directory traversal vulnerability in the Browse function (/browse URI) in Winamp Web Interface (Wawi) 7.5.13 and earlier allows remote authenticated users to list arbitrary directories via URL encoded backslashes ("%2F") in the path parameter. The attacker needs the "Browse" privilege to exploit this bug.
Publication date: Thu, 14 Dec 2006 07:28:00 +0000