CVE-2011-4807
14.12.2011, 00:55
Directory traversal vulnerability in main.php in phpAlbum 0.4.1.16 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the var1 parameter.
Vendor | Product | Version |
---|---|---|
phpalbum | phpalbum | 𝑥 ≤ 0.4.1.16 |
phpalbum | phpalbum | 0.2.1 |
phpalbum | phpalbum | 0.2.2 |
phpalbum | phpalbum | 0.2.3 |
phpalbum | phpalbum | 0.2.4 |
phpalbum | phpalbum | 0.3.0 |
phpalbum | phpalbum | 0.3.1 |
phpalbum | phpalbum | 0.3.1:fix01 |
phpalbum | phpalbum | 0.3.1:fix02 |
phpalbum | phpalbum | 0.3.2 |
phpalbum | phpalbum | 0.4.1-14 |
phpalbum | phpalbum | 0.4.1-14:fix01 |
phpalbum | phpalbum | 0.4.1-14:fix02 |
phpalbum | phpalbum | 0.4.1-14:fix03 |
phpalbum | phpalbum | 0.4.1-14:fix05 |
phpalbum | phpalbum | 0.4.1-14:fix06 |
phpalbum | phpalbum | 0.4.1.14 |
phpalbum | phpalbum | 0.4.1.15 |
𝑥
= Vulnerable software versions