Description
Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary files via ".." sequences in the e107language_e107cookie cookie to gsitemap.php.
Remediation
References
Related Vulnerabilities
SharePoint CVE-2024-30043 Vulnerability (CVE-2024-30043)
Apache HTTP Server Observable Timing Discrepancy Vulnerability (CVE-2026-33006)
MySQL CVE-2021-2180 Vulnerability (CVE-2021-2180)
WordPress Plugin Age Gate Security Bypass (2.17.0)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-0701)