Directory traversal vulnerability in admin/admin_hacks_list.php in Nivisec Hacks List 1.20 and earlier for phpBB, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. in the phpEx parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Hacks_list | Nivisec | * | 1.20 (including) |