Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%2f sequences in a URI.
| Software | From | Fixed in |
|---|---|---|
| salvo_g._tomaselli / weborf | 0.7 | 0.7.x |
| salvo_g._tomaselli / weborf | 0.9 | 0.9.x |
| salvo_g._tomaselli / weborf | 0.11 | 0.11.x |
| salvo_g._tomaselli / weborf | 0.3 | 0.3.x |
| salvo_g._tomaselli / weborf | - | 0.12.2.x |
| salvo_g._tomaselli / weborf | 0.6 | 0.6.x |
| salvo_g._tomaselli / weborf | 0.12 | 0.12.x |
| salvo_g._tomaselli / weborf | 0.12.1 | 0.12.1.x |
| salvo_g._tomaselli / weborf | 0.4 | 0.4.x |
| salvo_g._tomaselli / weborf | 0.5 | 0.5.x |
| salvo_g._tomaselli / weborf | 0.10 | 0.10.x |
| salvo_g._tomaselli / weborf | 0.8 | 0.8.x |