Directory traversal vulnerability in pnadminapi.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to read arbitrary files via a .. (dot dot) in the skin parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Postnuke | Postnuke_software_foundation | 0.760_rc3 (including) | 0.760_rc3 (including) |