Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence in the view parameter in the show_view action in the calendarmodule module, as demonstrated by executing PHP code through session files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Exponent_cms | Exponent | 0.96.3 (including) | 0.96.3 (including) |