|
SaveWebPortal contains a flaw that allows a remote attacker to access arbitrary files outside of the web path and/or execute arbitrary files. The issue is due to the 'menu_sx.php' script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the 'CONTENTS_Dir' variable.
|