Vulnerabilities (CVE)

Filtered by vendor Codologic Subscribe
Filtered by product Codoforum
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-9261 1 Codologic 1 Codoforum 2020-02-18 5.0 MEDIUM N/A
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to index.php.