Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating a block and specifying the target file as the source URL.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2002-05-18 21:00
Updated : 2016-10-17 19:14
NVD link : CVE-2001-1334
Mitre link : CVE-2001-1334
JSON object : View
CWE
Products Affected
phpslash
- phpslash