Directory traversal vulnerability in upgrade.php in nicecoder.com INDEXU 5.x allows remote attackers to include arbitrary local files via a .. (dot dot) in the gateway parameter.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Indexu | Nicecoder | * | 5.0 (including) |
References