MEDIUM
administration/telecharger.php in Cahier de texte 2.0 allows remote attackers to obtain unparsed content (source code) of files via the chemin parameter, as demonstrated using directory traversal sequences to obtain the MySQL username and password from conn_cahier_de_texte.php
Published Dec 4, 2006
4.3
MEDIUMCVSS 2.0
EPSS 2.91%
Description
Affected products
Remediation
References (6)
Change history (0)
No recorded changes yet.