Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating a block and specifying the target file as the source URL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpslash | Phpslash | 0.5.3.2 (including) | 0.5.3.2 (including) |
Phpslash | Phpslash | 0.6.1 (including) | 0.6.1 (including) |