Multiple directory traversal vulnerabilities in header.php in RicarGBooK 1.2.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) a lang cookie or (2) the language parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ricargbook | Ricargbook | 1.2.1 (including) | 1.2.1 (including) |