Directory traversal vulnerability in productionnu2/fileuploader.php in nuBuilder 10.04.20, and possibly other versions prior to 10.07.12, allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the dir parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
nusoftware nubuilder 09.09.23 |
||
nusoftware nubuilder 09.08.20 |
||
nusoftware nubuilder |
||
nusoftware nubuilder 09.07.24 |
||
nusoftware nubuilder 09.06.26 |
||
nusoftware nubuilder 09.06.10 |