Directory traversal vulnerability in print.php in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allows remote attackers to read arbitrary files via a .. (dot dot) in the ide parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Newsscript | Stefan_ernst | 0.5_beta (including) | 0.5_beta (including) |