Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary files via ".." sequences in the e107language_e107cookie cookie to gsitemap.php.
| Software | From | Fixed in |
|---|---|---|
| e107 / e107 | 0.7.5 | 0.7.5.x |