← Back to CVE List

CVE-2017-5480

Published: 2017-01-15T22:59Z
Last Modified: 2024-11-21T03:27Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Directory traversal vulnerability in inc/files/files.ctrl.php in b2evolution through 6.8.3 allows remote authenticated users to read or delete arbitrary files by leveraging back-office access to provide a .. (dot dot) in the fm_selected array parameter. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt