1 results (0.002 seconds)

CVSS: 7.5EPSS: 2%CPEs: 2EXPL: 1

Directory traversal vulnerability in v2demo/page.php in Jshop Server 1.x through 2.x allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xPage parameter. Vulnerabilidad de salto de directorio en v2demo/page.php en Jshop Server 1.x a 2.x, permite a atacantes remotos incluir y ejecutar ficheros locales de su elección mediante un .. (punto punto) en el parámetro xPage. • https://www.exploit-db.com/exploits/5325 http://www.securityfocus.com/bid/28501 https://exchange.xforce.ibmcloud.com/vulnerabilities/41524 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •