mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 15:15:46 +02:00
839 B
839 B
CVE-2011-4713
Description
Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the _ID parameter to (1) catalog/shopping_cart.php or (2) catalog/content.php.
POC
Reference
- http://seclists.org/fulldisclosure/2011/Nov/117
- http://seclists.org/fulldisclosure/2011/Nov/117
- http://www.exploit-db.com/exploits/18099
- http://www.exploit-db.com/exploits/18099
Github
No PoCs found on GitHub currently.