First published: Wed Apr 30 2014(Updated: )
Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include and execute arbitrary files via a .. (dot dot) in the (1) user_theme parameter to maincore.php; or remote authenticated administrators to delete arbitrary files via the (2) enable parameter to administration/user_fields.php or (3) file parameter to administration/db_backup.php.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Php-fusion Php-fusion | <=7.02.05 | |
Php-fusion Php-fusion | =7.02.01 | |
Php-fusion Php-fusion | =7.02.02 | |
Php-fusion Php-fusion | =7.02.03 | |
Php-fusion Php-fusion | =7.02.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.