routers/ajaxRouter.php in doorGets 7.0 has a web site physical path leakage vulnerability, as demonstrated by an ajax/index.php?uri=1234%5c request.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Doorgets_cms | Doorgets | 7.0 (including) | 7.0 (including) |
References