Lucene search

K
prionPRIOn knowledge basePRION:CVE-2014-9261
HistoryMar 23, 2015 - 4:59 p.m.

Directory traversal

2015-03-2316:59:00
PRIOn knowledge base
www.prio-n.com
2

7.2 High

AI Score

Confidence

Low

0.155 Low

EPSS

Percentile

95.9%

The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a … (dot dot) in the path parameter to index.php.

CPENameOperatorVersion
codoforumeq2.5.1

7.2 High

AI Score

Confidence

Low

0.155 Low

EPSS

Percentile

95.9%