ID:4016 - Exploit for Path traversal in PHP-Fusion - CVE-2013-1806
Published: August 11, 2020
PHP-Fusion
Link to public exploit:
Vulnerability description
The vulnerability allows a remote #AU# to read and manipulate data.
Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include and execute arbitrary files via a .. (dot dot) in the (1) user_theme parameter to maincore.php; or remote authenticated administrators to delete arbitrary files via the (2) enable parameter to administration/user_fields.php or (3) file parameter to administration/db_backup.php.