In Webgalamb up to and including 7.0, a system/ajax.php "wgmfile restore" directory traversal vulnerability could lead to arbitrary code execution by authenticated administrator users, because PHP files are restored under the document root directory.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ens webgalamb |