Directory traversal vulnerability in MyDMS 1.4.2 and other versions allows remote registered users to read arbitrary files via .. (dot dot) sequences in the URL.
Software | From | Fixed in |
---|---|---|
mydms / mydms | 1.4 | 1.4.x |
mydms / mydms | 1.4.1 | 1.4.1.x |
mydms / mydms | 1.4.2 | 1.4.2.x |