Description
Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, followed by a filename ending with "%00" and a .js filename.
Remediation
References
Related Vulnerabilities
WordPress Plugin Google XML Sitemaps Cross-Site Scripting (4.0.9)
WordPress Plugin LOGOSWARE SUITE Uploader Arbitrary File Upload (1.1.6)
Oracle HTTP Server Out-of-bounds Read Vulnerability (CVE-2019-3823)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-6455)
WordPress Plugin Participants Database SQL Injection (1.9.5.5)