|
SaveWebPortal contains a flaw that allows a remote attacker to access arbitrary files outside of the web path and/or execute arbitrary files. The issue is due to the 'menu_dx.php' script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the 'SITE_Path' variable.
|