index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and path disclosure.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ezdatabase | Indexcor | * | 2.1.1 (including) |