EC-CUBE 'LC_Page_ResizeImage.php' Directory Traversal Vulnerability

EC-CUBE is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.

Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.

Versions prior to EC-CUBE 2.12.5 are vulnerable.


 

Privacy Statement
Copyright 2010, SecurityFocus