Directory traversal vulnerability in 404.php in Drake CMS allows remote attackers to include and execute arbitrary local arbitrary files via a .. (dot dot) in the d_private parameter. NOTE: some of these details are obtained from third party information. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated We do not consider security reports valid until the first official release of Drake CMS.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Drake_cms | Drake_team | 0.3.7 (including) | 0.3.7 (including) |
Drake_cms | Drake_team | 0.3.7_beta (including) | 0.3.7_beta (including) |