Directory traversal vulnerability in Open-Realty CMS 2.5.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the select_users_template parameter to index.php.
| Software | From | Fixed in |
|---|---|---|
| open-realty / open-realty | - | 2.5.8.x |
| open-realty / open-realty | 2.3.4 | 2.3.4.x |
| open-realty / open-realty | 2.3.1 | 2.3.1.x |