CVE-2010-5281
26.11.2012, 23:55
Directory traversal vulnerability in ibrowser.php in the CMScout 2.09 IBrowser TinyMCE Plugin 1.4.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter. NOTE: some of these details are obtained from third party information.
Vendor | Product | Version |
---|---|---|
net4visions | ibrowser | 1.4.1 |
𝑥
= Vulnerable software versions
References