Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sn_admin_dir parameter.
References
Configurations
History
No history.
Information
Published : 2007-04-10 23:19
Updated : 2024-02-28 11:01
NVD link : CVE-2007-1932
Mitre link : CVE-2007-1932
CVE.ORG link : CVE-2007-1932
JSON object : View
Products Affected
scar4u
- scarnews
CWE