SB2015032301 - Path traversal in Codologic Codoforum
Published: March 23, 2015 Updated: August 9, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Path traversal (CVE-ID: CVE-2014-9261)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to index.php.
Remediation
Install update from vendor's website.