CVE-2016-10733

Publication date

2018-10-28 03:00:00

Family

mitre

State

PUBLISHED

Description

ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.