1 results (0.019 seconds)

CVSS: 7.5EPSS: 1%CPEs: 9EXPL: 3

Directory traversal vulnerability in getConfig.php in the Page Flip Image Gallery plugin 0.2.2 and earlier for WordPress, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the book_id parameter. NOTE: some of these details are obtained from third party information. Vulnerabilidad de salto de directorio en getConfig.php en el plugin Page Flip Image Gallery v0.2.2 y anteriores para WordPress, cuando magic_quotes_gpc están deshabilidadas, permite a atacantes remotos leer ficheros de su elección a través de ..(punto punto) en el parámetro "book_id". • https://www.exploit-db.com/exploits/7543 http://osvdb.org/50902 http://secunia.com/advisories/33274 http://securityreason.com/securityalert/4836 http://www.securityfocus.com/bid/32966 https://exchange.xforce.ibmcloud.com/vulnerabilities/47568 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •