An issue exists in XiaoCms 20141229. admin\controller\database.php allows arbitrary directory deletion via admin/index.php?c=database&a=import&paths[]=../ directory traversal.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
xiaocms xiaocms 20141229 |