Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via directory traversal sequences in the controller parameter in a show_report action.
References
Configurations
History
No history.
Information
Published : 2011-09-14 02:56
Updated : 2012-02-14 04:02
NVD link : CVE-2010-4835
Mitre link : CVE-2010-4835
CVE.ORG link : CVE-2010-4835
JSON object : View
Products Affected
oneorzero
- aims
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')