Menu

#20 Directory traversal in tiki-listmovies.php (CVE-2007-6528)

new
Chuck
None
TikiWiki
Medium
Current
2011-12-20
2011-12-20
anonymous
No

A remote attacker can craft the "movies" parameter to run a directory traversal attack through a ".." sequence and read the first 1000 bytes of any arbitrary file.

Discussion


Log in to post a comment.