pixlie.php in Pixlie 1.7 allows remote attackers to trigger the reading and JPEG image processing of files in a remote directory tree via a URL in the root parameter. NOTE: this can be leveraged for traffic amplification or other denial of service.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pixlie | Pixlie | 1.7 (including) | 1.7 (including) |