#VU4748 Directory traversal in b2evolution - CVE-2017-5480
Published: January 16, 2017 / Updated: January 16, 2017
b2evolution
b2evolution.net
Description
The vulnerability allows a remote attacker to view arbitrary files on vulnerable system.
The vulnerability exists due to insufficient sanitization of user-supplied data passed "fm_selected" array parameter in "inc/files/files.ctrl.php" script. A remote authenticated attacker can use directory traversal sequences (e.g. ../) to view contents of arbitrary files on vulnerable system.
Successful exploitation of the vulnerability may allow an attacker to obtain sensitive ad system information.