CVE

Id
79344  
CVE No.
CVE-2015-2067  
Status
Candidate  
Description
Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.  
Phase
Assigned (20150224)  
Votes
None (candidate not yet proposed)  
Comments