CVE
- Id
- 93955
- CVE No.
- CVE-2016-7135
- Status
- Candidate
- Description
- Directory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x through 4.3.11 allows remote administrators to read arbitrary files via a .. (dot dot) in the path parameter in a getFile action to Plone/++theme++barceloneta/@@plone.resourceeditor.filemanager-actions.
- Phase
- Assigned (20160905)
- Votes
- None (candidate not yet proposed)
- Comments