CVE-2019-25579
EUVD-2019-1990221.03.2026, 16:16
phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the path parameter. Attackers can send requests to the jQueryFileUploadmaster server endpoint with traversal sequences ../../../../../../ to list and retrieve files outside the intended directory.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| codnloc | phptransformer | 2016.9 |
𝑥
= Vulnerable software versions