Directory traversal vulnerability in function_foot_1.inc.php for Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to read arbitrary files via .. (dot dot) sequences terminated by a null character in the $designNo variable, which is part of an include function call.
Name | Vendor | Start Version | End Version |
---|---|---|---|
123tkshop | Thorsten_korner | 0.2 (including) | 0.2 (including) |
123tkshop | Thorsten_korner | 0.3 (including) | 0.3 (including) |