Directory traversal vulnerability in admin/defaults.php in PHPlist 2.10.1 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) in the selected%5B%5D parameter in an HTTP POST request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phplist | Tincan | * | 2.10.1 (including) |