Path traversal in ZNC - CVE-2018-14056
Published: July 30, 2018
ZNC
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The vulnerability exists due to path traversal flaw when handling malicious input passed via ../ in a web skin name. A remote unauthenticated attacker can supply specially crafted input to access files outside of the intended skins directories.