Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Meekaah

#36491of 53,622
7.5Total CVSS
Vulnerabilities · 1
PT-2009-2645
7.5
2009-09-08
Xoops · Uploader · CVE-2008-7178
**Name of the Vulnerable Software and Affected Versions** Uploader module version 1.1 for XOOPS **Description** The issue allows remote attackers to read arbitrary files due to a directory traversal vulnerability. This is achieved by including a .. (dot dot) in the `filename` parameter within a downloadfile action to "index.php". **Recommendations** For Uploader module version 1.1, consider restricting access to the downloadfile action in index.php to minimize the risk of exploitation. Avoid using the `filename` parameter in the affected API endpoint until the issue is resolved.