Security Advisory

CVE-2018-13123

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-07-03 22:00:00
Last updated 2024-08-05 08:52:50
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated by ?i=etc/&f=passwd&p=raw_view for the /etc/passwd file.