Directory traversal vulnerability in download.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 allows remote malicious users to read arbitrary files via a .. (dot dot) in the upload_filename parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
truc truc 0.11 |