CVE-2011-4810: Path Traversal
Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read arbitrary files via the templatefile parameter to (1) submitticket.php and (2) downloads.php, and (3) the report parameter to admin/reports.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4810?
CVE-2011-4810 has a high severity level due to its potential to allow unauthorized access to sensitive files.
How do I fix CVE-2011-4810?
To fix CVE-2011-4810, update WHMCompleteSolution to a version that is not vulnerable, preferably the latest release.
What types of attacks can CVE-2011-4810 enable?
CVE-2011-4810 can enable attackers to perform directory traversal attacks to read arbitrary files on the server.
Which versions of WHMCompleteSolution are affected by CVE-2011-4810?
CVE-2011-4810 affects WHMCompleteSolution versions 3.x and 4.x, specifically 3.0.0 to 4.5.2.
What specific files are vulnerable in CVE-2011-4810?
CVE-2011-4810 allows exploitation through the templatefile parameter in submitticket.php and downloads.php, and the report parameter in admin/reports.php.