1 results (0.033 seconds)

CVSS: 6.8EPSS: 8%CPEs: 2EXPL: 4

Directory traversal vulnerability in richedit/keyboard.php in eCardMAX HotEditor (Hot Editor) 4.0, and the HotEditor plugin for MyBB, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the first parameter. Vulnerabilidad de salto de directorio en richedit/keyboard.php de eCardMAX HotEditor (Hot Editor) 4.0, y el plugin HotEditor para MyBB, permite a atacantes remotos incluir y ejecutar código de su elección mediante una secuencia .. (punto punto) en el primer parámetro. • https://www.exploit-db.com/exploits/29827 http://osvdb.org/34776 http://secunia.com/advisories/24825 http://securityreason.com/securityalert/2533 http://www.expw0rm.com/hot-editor-v40-local-file-inclusion_no113.html http://www.expw0rm.com/mybb-hot-editor-plugin-local-file-inclusion_no114.html http://www.securityfocus.com/archive/1/465092/100/0/threaded http://www.securityfocus.com/archive/1/465094/100/0/threaded http://www.securityfocus.com/bid/23377 http://www.vupen.com&# •