CVE-2014-3855 Information

Description

Directory traversal vulnerability in download.py in Pyplate 0.08 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

Reference

http://www.openwall.com/lists/oss-security/2014/05/14/3 http://www.openwall.com/lists/oss-security/2014/05/23/1

Share on: