|
Dokeos 1.8.5 and earlier contains a flaw that allows a remote attacker to disclose arbitrary files outside of the web path. The issue is due to unspecified errors not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the unspecified variable(s).
|