Description
Directory traversal vulnerability in thumb.php in Clear Content 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected products
- allisclear / clear_content1.1 – 1.1
References
- VENDOR_ADVISORYhttp://secunia.com/advisories/35726
- MISChttp://www.osvdb.org/55743