Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Envolution | Envolution | 1.1.0 (including) | 1.1.0 (including) |