Directory traversal vulnerability in pnadminapi.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to read arbitrary files via a .. (dot dot) in the skin parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Postnuke | Postnuke_software_foundation | 0.760_rc3 (including) | 0.760_rc3 (including) |