CVE-2010-0799 Information

Description

Directory traversal vulnerability in misc/tell_a_friend/tell.php in phpunity.newsmanager allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.

Reference

http://osvdb.org/62036 http://packetstormsecurity.org/1001-exploits/phpunity-lfi.txt http://secunia.com/advisories/38409 http://www.exploit-db.com/exploits/11290

Share on: