Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive information via a .. (dot dot) in the icodir parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Exponent_cms | Exponent | 0.96.5_rc1 (including) | 0.96.5_rc1 (including) |
Exponent_cms | Exponent | 0.96.6_alpha (including) | 0.96.6_alpha (including) |