CVE-2010-1003
19.03.2010, 20:30
Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langname parameter.
Vendor | Product | Version |
---|---|---|
efrontlearning | efront | 3.5.0 |
efrontlearning | efront | 3.5.1 |
efrontlearning | efront | 3.5.2 |
efrontlearning | efront | 3.5.3 |
efrontlearning | efront | 3.5.4 |
efrontlearning | efront | 3.5.5 |
𝑥
= Vulnerable software versions
References