MidnightBSD

Advisories for andy_stedemos

CVE-2009-4816 MEDIUM

Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
andy_stedemos the_uploader 2.0.0