Security Advisory

CVE-2008-6002

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-01-28 15:00:00
Last updated 2024-08-07 11:13:13
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Absolute path traversal vulnerability in sendfile.php in web-cp 0.5.7, when register_globals is enabled, allows remote attackers to read arbitrary files via a full pathname in the filelocation parameter.