Directory traversal vulnerability in the delete function in IMCE before 1.6, a Drupal module, allows remote authenticated users to delete arbitrary files via .. sequences.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Imce_module |
Drupal |
* |
1.5 (including) |
References