10 lines
No EOL
455 B
Text
10 lines
No EOL
455 B
Text
source: https://www.securityfocus.com/bid/53616/info
|
|
|
|
Acuity CMS is prone to a directory-traversal vulnerability and an arbitrary-file-upload vulnerability.
|
|
|
|
An attacker can exploit these issues to obtain sensitive information, to upload arbitrary code, and run it in the context of the webserver process.
|
|
|
|
Acuity CMS 2.6.2 is vulnerable; prior versions may also be affected.
|
|
|
|
|
|
http://www.example.com/admin/file_manager/browse.asp?field=&form=&path=../../ |