First published: Tue Mar 06 2007(Updated: )
Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demonstrated by uploading a GIF image using AddDownload or injecting PHP code into a log file, then accessing it.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MAXdev MDPro | <=1.0.76 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.