Security Advisory

CVE-2012-1671

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-10-08 23:00:00
Last updated 2024-09-17 03:58:42
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Directory traversal vulnerability in index.php in phpPaleo 4.8b155 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.