Back to search
CVE-2014-9261
Published: Mar 23, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to index.php.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
119412
vdb-entry
x_refsource_OSVDB
36320
exploit
x_refsource_EXPLOIT-DB
https://codoforum.com/documentation/roadmap
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now