Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via .. (dot dot) sequences in the $_CCFG[_PKG_PATH_DBSE] variable.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpcoin | Coinsoft_technologies | 1.2.2 (including) | 1.2.2 (including) |