Directory traversal vulnerability in classes/captcha/captcha.jpg.php in Drake CMS allows remote attackers to read arbitrary files or list arbitrary directories, and obtain the installation path, via a .. (dot dot) in the d_private parameter. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated We do not consider security reports valid until the first official release of Drake CMS.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Drake_cms | Drake_team | * | * |