Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating a block and specifying the target file as the source URL.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
phpslash phpslash 0.5.3.2 |
||
phpslash phpslash 0.6.1 |