CVE-2011-4713
08.12.2011, 19:55
Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the _ID parameter to (1) catalog/shopping_cart.php or (2) catalog/content.php.
Vendor | Product | Version |
---|---|---|
oscss | oscss | 𝑥 ≤ 2.10 |
oscss | oscss | 1.0 |
oscss | oscss | 1.1 |
oscss | oscss | 1.2.2:rc_c |
oscss | oscss | 2.10:prerc_f |
oscss | oscss | 2.10:prerc_g1 |
oscss | oscss | 2.10:prerc12 |
oscss | oscss | 2.10:prerc30 |
oscss | oscss | 2.10:rc5 |
𝑥
= Vulnerable software versions
References