name:BOA Web Server 0.94.14 - Access to arbitrary files as privileges
author:0x_Akoko
severity:high
description:The server allows the injection of "../.." using the FILECAMERA variable sent by GET to read files with root privileges. Without using access credentials.