Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating a block and specifying the target file as the source URL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Phpslash | Phpslash | 0.5.3.2 (including) | 0.5.3.2 (including) |
| Phpslash | Phpslash | 0.6.1 (including) | 0.6.1 (including) |