CVE-2015-5079

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
28/02/2018
Last modified:
29/04/2019

Description

Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the dl parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:blackcat-cms:blackcat_cms:*:*:*:*:*:*:*:* 1.1.2 (excluding)