Description
Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full path in the URL parameter to modules/Feeds/Feed.php, which places the contents into a related cache file in the .cache/feeds directory.
Remediation
References
Related Vulnerabilities
Piwigo Improper Access Control Vulnerability (CVE-2016-10105)
WordPress Denial of Service Vulnerability (3.5 - 3.6.1)
WordPress 4.0.x PHP Object Injection (4.0 - 4.0.32)
WordPress Plugin WordPress Shortcodes-Shortcodes Ultimate Cross-Site Scripting (5.10.1)
Django Improper Input Validation Vulnerability (CVE-2010-4535)