|
e107 FileDownload Plugin Arbitrary File Upload and Remote File Disclosure Vulnerabilities
The FileDownload Plugin for e107 is prone to an arbitrary file-upload vulnerability and a remote file-disclosure vulnerability because the application fails to adequately sanitize user-supplied input. An attacker can exploit these issues to upload a file and view local files in the context of the web server process, which may aid in further attacks. FileDownload 1.1 is vulnerable; other versions may also be affected. |
|
Privacy Statement |