CVE-2018-9205 – Drupal avatar_uploader v7.x-1.0-beta8 - Arbitrary File Disclosure
https://notcve.org/view.php?id=CVE-2018-9205
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path. Vulnerabilidad en avatar_uploader v7.x-1.0-beta8 en la que el código en view.php no verifica usuarios o sanea la ruta del archivo. • https://www.exploit-db.com/exploits/44501 http://www.vapidlabs.com/advisory.php?v=202 https://www.drupal.org/project/avatar_uploader https://www.drupal.org/project/avatar_uploader/issues/2957966 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2014-9155
https://notcve.org/view.php?id=CVE-2014-9155
Directory traversal vulnerability in the Avatar Uploader module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta6 for Drupal allows remote authenticated users to read arbitrary files via a .. (dot dot) in the path of a cropped picture in the uploader panel. Vulnerabilidad de salto de directorio en el módulo Avatar Uploader 6.x-1.x anterior a 6.x-1.2 y 7.x-1.x anterior a 7.x-1.0-beta6 para Drupal permite a usuarios remotos autenticados leer ficheros arbitrarios a través de un .. (punto punto) en la ruta de una imagen recortada en el panel del cargador. • https://www.drupal.org/node/2330759 https://www.drupal.org/node/2330763 https://www.drupal.org/node/2332169 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •