MEDIUM
Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demonstrated by uploading a GIF image using AddDownload or injecting PHP code into a log file, then accessing it
Published Mar 6, 2007
6.0
MEDIUMCVSS 2.0
EPSS 1.61%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.