5
CVSSv2

CVE-2014-3777

Published: 16/07/2014 Updated: 16/07/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in Reportico PHP Report Designer prior to 4.0 allows remote malicious users to read arbitrary files via a .. (dot dot) in the xmlin parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

reportico php report designer 2.3.1

reportico php report designer 2.3

reportico php report designer 2.2

reportico php report designer 2.1

reportico php report designer 2.0

reportico php report designer

reportico php report designer 3.2

reportico php report designer 3.1

reportico php report designer 3.0

reportico php report designer 1.0.4

reportico php report designer 1.0.3

reportico php report designer 1.0.2

reportico php report designer 1.0.1

reportico php report designer 2.7

reportico php report designer 2.5

reportico php report designer 2.0.1

reportico php report designer 1.0.6

reportico php report designer 2.6

reportico php report designer 2.4

reportico php report designer 1.0.5

reportico php report designer 1.0.0

Exploits

All versions of Reportico prior to version 40 leak administrative credentials ...