BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote malicious users to bypass authentication via a ..\ substring, as demonstrated by a launch.php?bigtree_htaccess_url=admin/images/..\ URI.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
bigtreecms bigtree_cms 4.2.23 |