Total vulnerabilities in the database
Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter.
Software | From | Fixed in |
---|---|---|
phpwebthings / phpwebthings | 0.1 | 0.1.x |
phpwebthings / phpwebthings | 0.2 | 0.2.x |
phpwebthings / phpwebthings | 0.4 | 0.4.x |
phpwebthings / phpwebthings | 1.5.1 | 1.5.1.x |
phpwebthings / phpwebthings | 0.4.1 | 0.4.1.x |
phpwebthings / phpwebthings | 1.0 | 1.0.x |
phpwebthings / phpwebthings | - | 1.5.2.x |
phpwebthings / phpwebthings | 0.2b | 0.2b.x |
phpwebthings / phpwebthings | 1.5.0 | 1.5.0.x |
phpwebthings / phpwebthings | 1.1a | 1.1a.x |
phpwebthings / phpwebthings | 0.3 | 0.3.x |
phpwebthings / phpwebthings | 0.4.2 | 0.4.2.x |
phpwebthings / phpwebthings | 0.6.0 | 0.6.0.x |
phpwebthings / phpwebthings | 1.4 | 1.4.x |