emlog up to and including 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tpl=../ directory traversal.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
emlog emlog 6.0.0 |
||
emlog emlog |