CVE-2018-6022
23.01.2018, 06:29
Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to delete arbitrary files by leveraging back-office access to provide a ..\ in the param.path parameter.
Vendor | Product | Version |
---|---|---|
5none | nonecms | 𝑥 ≤ 1.3.0 |
𝑥
= Vulnerable software versions