MEDIUM
OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd
Published Mar 18, 2004
5.0
MEDIUMCVSS 2.0
EPSS 3.22%
Description
Affected products
Remediation
References (5)
Change history (0)
No recorded changes yet.