Directory traversal vulnerability in session.php in JSBoard 2.0.9 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the table parameter.
Software | From | Fixed in |
---|---|---|
jsboard / jsboard | 2.0.7 | 2.0.7.x |
jsboard / jsboard | 2.0.8 | 2.0.8.x |
jsboard / jsboard | 2.0.9 | 2.0.9.x |