Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the languagepack parameter to (1) jax_petitionbook.php or (2) smileys.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jax_petition_book | Jax_scripts | 1.0.3.06 (including) | 1.0.3.06 (including) |