Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via directory traversal sequences in the controller parameter in a show_report action.
References
Configurations
Information
Published : 2011-09-13 19:56
Updated : 2012-02-13 20:02
NVD link : CVE-2010-4835
Mitre link : CVE-2010-4835
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
oneorzero
- aims