CVE-2011-4832 Information

Description

Directory traversal vulnerability in CaupoShop Pro 2.x CaupoShop Classic 3.01 and CaupoShop Pro 3.70 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter in a template action.

Reference

http://secunia.com/advisories/46704 http://www.exploit-db.com/exploits/18066 http://www.osvdb.org/76871 http://www.securityfocus.com/bid/50530 https://exchange.xforce.ibmcloud.com/vulnerabilities/71136

Share on: