HIGH
Absolute path traversal vulnerability in fckeditor/editor/filemanager/browser/default/connectors/php/connector.php in UNAK-CMS 1.5.5 allows remote attackers to include and execute arbitrary local files via a full pathname in the Dirroot parameter, a different vulnerability than CVE-2006-4890.1
Published Aug 10, 2008
7.5
HIGHCVSS 2.0
EPSS 2.90%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.