DansGuardian before 2.7.7-2 allows remote attackers to bypass URL filters via a ".." in the request.
| Software | From | Fixed in |
|---|---|---|
| daniel_barron / dansguardian | 2.7.7.1_beta | 2.7.7.1_beta.x |
| daniel_barron / dansguardian | 2.7.6 | 2.7.6.x |
| daniel_barron / dansguardian | 2.7.5 | 2.7.5.x |
| daniel_barron / dansguardian | 2.7.3 | 2.7.3.x |
| daniel_barron / dansguardian | 2.7.7 | 2.7.7.x |