← Back to CVE List

CVE-2020-15712

Published: 2020-07-28T14:15Z
Last Modified: 2024-11-21T05:06Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
rConfig 3.9.5 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a crafted request to the ajaxGetFileByPath.php script containing hexadecimal encoded "dot dot" sequences (%2f..%2f) in the path parameter to view arbitrary files on the system. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt