cve/2017/CVE-2017-9428.md
2024-06-18 02:51:15 +02:00

703 B

CVE-2017-9428

Description

A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windows, allowing attackers to read arbitrary files via ..\ sequences in the directory parameter.

POC

Reference

Github

No PoCs found on GitHub currently.