Security Advisory

CVE-2014-9261

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-03-23 16:00:00
Last updated 2024-08-06 13:40:24
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to index.php.