Security Advisory

CVE-2008-7055

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-08-24 19:00:00
Last updated 2024-08-07 11:49:03
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

module.php in ezContents 2.0.3 allows remote attackers to bypass the directory traversal protection mechanism to include and execute arbitrary local files via "....//" (doubled dot dot slash) sequences in the link parameter, which is not properly filtered using the str_replace function.