Description
Directory traversal vulnerability in the dotTailLogServlet in dotCMS before 3.5.1 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the fileName parameter.
Remediation
References
Related Vulnerabilities
MediaWiki Incorrect Authorization Vulnerability (CVE-2021-41801)
Tornado URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-28370)
WordPress Plugin BitMonet Cross-Site Scripting (1.0)
WordPress Other Vulnerability (CVE-2006-6017)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-3745)