LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the index.php f1 variable, aka Local File Inclusion. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Lionwiki | Lionwiki | * | 3.2.12 (excluding) |