Drupal avatar_uploader v7.x-1.0-beta8 - Local File Inclusion
In avatar_uploader v7.x-1.0-beta8 the view.php program doesn't restrict file paths, allowing unauthenticated users to retrieve arbitrary files.
PoC 已收录avatar
CVSS7.5EPSS 55.1%
共找到 1 条公开漏洞记录
In avatar_uploader v7.x-1.0-beta8 the view.php program doesn't restrict file paths, allowing unauthenticated users to retrieve arbitrary files.