Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sn_admin_dir parameter.
References
Configurations
Information
Published : 2007-04-10 16:19
Updated : 2017-10-10 18:32
NVD link : CVE-2007-1932
Mitre link : CVE-2007-1932
JSON object : View
CWE
Products Affected
scar4u
- scarnews


