看板 Bugtraq 關於我們 聯絡資訊
This isn't a directory traversal, the code is simply output on to the page as <frame src="..."> (sanitised of course), so they can only access what is available in the physical domain. Scott MacVicar Development Team, vBulletin