mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 19:17:37 +02:00
753 B
753 B
CVE-2014-3777
Description
Directory traversal vulnerability in Reportico PHP Report Designer before 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the xmlin parameter.
POC
Reference
- http://packetstormsecurity.com/files/127280/Reportico-Admin-Credential-Leak.html
- http://packetstormsecurity.com/files/127280/Reportico-Admin-Credential-Leak.html
Github
No PoCs found on GitHub currently.