danielelkabes/Vulnerability-Reports

danielelkabes/Vulnerability-Reports

GitHubGitHub
Unavailable
This project is no longer available (or publicly accessible) from GitHub
Releases0
Reports about new security vulnerabilities

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

A downloadFile.php download_file path traversal vulnerability in rConfig through 3.9.3 allows attackers to list files in arbitrary folders and potentially download files. NOTE: the discoverer later reported that there was not a "fully working exploit.