Security Advisory

CVE-2010-2850

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2010-07-23 20:00:00
Last updated 2024-08-07 02:46:48
Assigner mitre
State PUBLISHED

Description

Directory traversal vulnerability in productionnu2/fileuploader.php in nuBuilder 10.04.20, and possibly other versions before 10.07.12, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dir parameter.