Directory traversal vulnerability in Upload/engine.php in Chevereto 1.9.1 allows remote malicious users to determine the existence of arbitrary files via a .. (dot dot) in the v parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
chevereto chevereto 1.91 |