Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in the load parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Citrusdb | Citrusdb | * | 0.3.6 (including) |