1 results (0.001 seconds)
CVSS: 7.5EPSS: 2%CPEs: 1EXPL: 2
CVE-2018-9205 – Drupal avatar_uploader v7.x-1.0-beta8 - Arbitrary File Disclosure
https://notcve.org/view.php?id=CVE-2018-9205
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path. Vulnerabilidad en avatar_uploader v7.x-1.0-beta8 en la que el código en view.php no verifica usuarios o sanea la ruta del archivo. • https://www.exploit-db.com/exploits/44501 http://www.vapidlabs.com/advisory.php?v=202 https://www.drupal.org/project/avatar_uploader https://www.drupal.org/project/avatar_uploader/issues/2957966 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •